CVE-2019-6568
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- siemens/cp1604 firmware · siemens/cp1616 firmware · siemens/simatic rf185c firmware · siemens/simatic cp343-1 advanced firmware · siemens/simatic cp443-1 firmware · siemens/simatic cp443-1 advanced firmware · siemens/simatic et 200 sp open controller cpu 1515sp pc firmware · siemens/simatic et 200 sp open controller cpu 1515sp pc2 firmware · siemens/simatic hmi comfort outdoor panels firmware · siemens/simatic hmi comfort panels firmware · siemens/simatic hmi ktp mobile panels ktp400f firmware · siemens/simatic hmi ktp mobile panels ktp700 firmware · siemens/simatic hmi ktp mobile panels ktp700f firmware · siemens/simatic hmi ktp mobile panels ktp900 firmware · siemens/simatic hmi ktp mobile panels ktp900f firmware · siemens/simatic cp443-1 opc ua · siemens/simatic ipc diagmonitor · siemens/simatic s7-1500 software controller · siemens/simatic s7-plcsim advanced · siemens/simatic wincc runtime advanced · +33 more
- Source
- productcert@siemens.com
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-480230.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-480230.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.