Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-13946


Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.5, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 101 products from siemens, from siemens, from siemens and 98 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2020, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2020-02-11T16:15:15.023

Last Modified

2024-11-21T04:25:45.080

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Secondary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens dk_standard_ethernet_controller * Yes
Application siemens profinet_driver < 2.1 Yes
Application siemens simatic_ipc_support * Yes
Operating System siemens ek-ertec_200_firmware < 4.5 Yes
Hardware siemens ek-ertec_200 - No
Operating System siemens ek-ertec_200p_firmware < 4.6 Yes
Hardware siemens ek-ertec_200p - No
Operating System siemens ruggedcom_rm1224_firmware < 4.3 Yes
Hardware siemens ruggedcom_rm1224 - No
Operating System siemens scalance_m-800_firmware < 4.3 Yes
Hardware siemens scalance_m-800 - No
Operating System siemens scalance_s615_firmware < 4.3 Yes
Hardware siemens scalance_s615 - No
Operating System siemens scalance_w700_ieee_802.11n_firmware ≤ 6.0.1 Yes
Hardware siemens scalance_w700_ieee_802.11n - No
Operating System siemens scalance_xc-200_firmware * Yes
Hardware siemens scalance_xc-200 - No
Operating System siemens scalance_xf-200_firmware * Yes
Hardware siemens scalance_xf-200 - No
Operating System siemens scalance_xp-200_firmware * Yes
Hardware siemens scalance_xp-200 - No
Operating System siemens scalance_xb-200_firmware * Yes
Hardware siemens scalance_xb-200 - No
Operating System siemens scalance_x-200irt_firmware < 5.3 Yes
Hardware siemens scalance_x-200irt - No
Operating System siemens scalance_xr-300wg_firmware < 3.0 Yes
Hardware siemens scalance_xr-300wg - No
Operating System siemens scalance_x-300_firmware * Yes
Hardware siemens scalance_x-300 - No
Operating System siemens scalance_xb-200_firmware < 3.0 Yes
Hardware siemens scalance_xb-200 - No
Operating System siemens scalance_xc-200_firmware < 3.0 Yes
Hardware siemens scalance_xc-200 - No
Operating System siemens scalance_xp-200_firmware < 3.0 Yes
Hardware siemens scalance_xp-200 - No
Operating System siemens scalance_xf-200ba_firmware < 3.0 Yes
Hardware siemens scalance_xf-200ba - No
Operating System siemens scalance_xr-300wg_firmware < 3.0 Yes
Hardware siemens scalance_xr-300wg - No
Operating System siemens scalance_x-400_firmware < 6.0 Yes
Hardware siemens scalance_x-400 - No
Operating System siemens scalance_xm-400_firmware < 6.0 Yes
Hardware siemens scalance_xm-400 - No
Operating System siemens scalance_xr524_firmware < 6.0 Yes
Hardware siemens scalance_xr524 - No
Operating System siemens scalance_xr526_firmware < 6.0 Yes
Hardware siemens scalance_xr526 - No
Operating System siemens scalance_xr528_firmware < 6.0 Yes
Hardware siemens scalance_xr528 - No
Operating System siemens scalance_xr552_firmware < 6.0 Yes
Hardware siemens scalance_xr552 - No
Operating System siemens simatic_cp_1616_firmware < 2.8 Yes
Hardware siemens simatic_cp_1616 - No
Operating System siemens simatic_cp_1604_firmware < 2.8 Yes
Hardware siemens simatic_cp_1604 - No
Operating System siemens simatic_cp_343-1_firmware * Yes
Hardware siemens simatic_cp_343-1 - No
Operating System siemens simatic_cp_343-1_advanced_firmware * Yes
Hardware siemens simatic_cp_343-1_advanced - No
Operating System siemens simatic_cp_343-1_erpc_firmware * Yes
Hardware siemens simatic_cp_343-1_erpc - No
Operating System siemens simatic_cp_343-1_lean_firmware * Yes
Hardware siemens simatic_cp_343-1_lean - No
Operating System siemens simatic_cp_443-1_firmware * Yes
Hardware siemens simatic_cp_443-1 - No
Operating System siemens simatic_cp_443-1_advanced_firmware * Yes
Hardware siemens simatic_cp_443-1_advanced - No
Operating System siemens simatic_cp_443-1_opc_ua_firmware * Yes
Hardware siemens simatic_cp_443-1_opc_ua - No
Operating System siemens simatic_et200al_im_157-1_pn_firmware * Yes
Hardware siemens simatic_et200al_im_157-1_pn - No
Operating System siemens simatic_et200m_im153-4_pn_io_hf_firmware * Yes
Hardware siemens simatic_et200m_im153-4_pn_io_hf - No
Operating System siemens simatic_et200m_im153-4_pn_io_st_firmware * Yes
Hardware siemens simatic_et200m_im153-4_pn_io_st - No
Operating System siemens simatic_et200mp_im155-5_pn_hf_firmware < 4.2.0 Yes
Hardware siemens simatic_et200mp_im155-5_pn_hf - No
Operating System siemens simatic_et200mp_im155-5_pn_st_firmware < 4.1.0 Yes
Hardware siemens simatic_et200mp_im155-5_pn_st - No
Operating System siemens simatic_et200s_firmware * Yes
Hardware siemens simatic_et200s - No
Operating System siemens simatic_et200sp_im155-6_pn_basic_firmware * Yes
Hardware siemens simatic_et200sp_im155-6_pn_basic - No
Operating System siemens simatic_et200sp_im155-6_pn_hf_firmware < 3.3.1 Yes
Hardware siemens simatic_et200sp_im155-6_pn_hf - No
Operating System siemens simatic_et200sp_im155-6_pn_st_firmware < 4.1.0 Yes
Hardware siemens simatic_et200sp_im155-6_pn_st - No
Operating System siemens simatic_et200ecopn_firmware * Yes
Hardware siemens simatic_et200ecopn - No
Operating System siemens simatic_et200pro_firmware * Yes
Hardware siemens simatic_et200pro - No
Operating System siemens im_154-3_pn_hf_firmware * Yes
Hardware siemens im_154-3_pn_hf - No
Operating System siemens im_154-4_pn_hf_firmware * Yes
Hardware siemens im_154-4_pn_hf - No
Operating System siemens simatic_mv440_firmware * Yes
Hardware siemens simatic_mv440 - No
Operating System siemens simatic_mv420_firmware * Yes
Hardware siemens simatic_mv420 - No
Operating System siemens simatic_pn\/pn_coupler_firmware * Yes
Hardware siemens simatic_pn\/pn_coupler - No
Operating System siemens simatic_rf180c_firmware * Yes
Hardware siemens simatic_rf180c - No
Operating System siemens simatic_rf182c_firmware * Yes
Hardware siemens simatic_rf182c - No
Operating System siemens simatic_rf600_firmware < 3.0 Yes
Hardware siemens simatic_rf600 - No
Operating System siemens sinamics_dcp_firmware < 1.3 Yes
Hardware siemens sinamics_dcp - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For siemens's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.