Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10939


A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3), TIM 4R-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 4R-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3). The affected versions contain an open debug port that is available under certain specific conditions. The vulnerability is only available if the IP address is configured to 192.168.1.2. If available, the debug port could be exploited by an attacker with network access to the device. No user interaction is required to exploit this vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the affected device. At the stage of publishing this security advisory no public exploitation is known.


Published

2020-04-14T20:15:14.293

Last Modified

2024-11-21T04:20:11.797

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-489
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens tim_3v-ie_firmware < 2.8 Yes
Hardware siemens tim_3v-ie - No
Operating System siemens tim_3v-ie_advanced_firmware < 2.8 Yes
Hardware siemens tim_3v-ie_advanced - No
Operating System siemens tim_4r-ie_firmware < 3.3 Yes
Hardware siemens tim_4r-ie - No
Operating System siemens tim_3v-ie_dnp3_firmware < 2.8 Yes
Hardware siemens tim_3v-ie_dnp3 - No
Operating System siemens tim_4r-ie_dnp3_firmware < 3.3 Yes
Hardware siemens tim_4r-ie_dnp3 - No

References