SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6569

An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.

CRITICAL 9.1EPSS 1.33%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS
1.33% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-440
Affected
siemens/scalance x-200 firmware · siemens/scalance x-300 firmware · siemens/scalance xp-200 firmware · siemens/scalance xc-200 firmware · siemens/scalance xf-200 firmware
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.