Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-19300


A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE530S COATED, SIDOOR ATE531S, SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0), SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L (6ES7144-6JF00-0BB0), SIMATIC ET 200eco PN, CM 4x IO-Link, M12-L (6ES7148-6JE00-0BB0), SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L (6ES7148-6JG00-0BB0), SIMATIC ET 200eco PN, CM 8x IO-Link, M12-L (6ES7148-6JJ00-0BB0), SIMATIC ET 200eco PN, DI 16x24VDC, M12-L (6ES7141-6BH00-0BB0), SIMATIC ET 200eco PN, DI 8x24VDC, M12-L (6ES7141-6BG00-0BB0), SIMATIC ET 200eco PN, DIQ 16x24VDC/2A, M12-L (6ES7143-6BH00-0BB0), SIMATIC ET 200eco PN, DQ 8x24VDC/0,5A, M12-L (6ES7142-6BG00-0BB0), SIMATIC ET 200eco PN, DQ 8x24VDC/2A, M12-L (6ES7142-6BR00-0BB0), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0), SIMATIC ET 200pro IM 154-8 PN/DP CPU (6ES7154-8AB01-0AB0), SIMATIC ET 200pro IM 154-8F PN/DP CPU (6ES7154-8FB01-0AB0), SIMATIC ET 200pro IM 154-8FX PN/DP CPU (6ES7154-8FX00-0AB0), SIMATIC ET 200S IM 151-8 PN/DP CPU (6ES7151-8AB01-0AB0), SIMATIC ET 200S IM 151-8F PN/DP CPU (6ES7151-8FB01-0AB0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants), SIMATIC ET 200SP IM 155-6 PN HF (6ES7155-6AU00-0CN0), SIMATIC ET 200SP IM 155-6 PN/2 HF (6ES7155-6AU01-0CN0), SIMATIC ET 200SP IM 155-6 PN/3 HF (6ES7155-6AU30-0CN0), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants), SIMATIC MICRO-DRIVE PDC, SIMATIC PN/MF Coupler (6ES7158-3MU10-0XA0), SIMATIC PN/PN Coupler (6ES7158-3AD10-0XA0), SIMATIC S7-1200 CPU family (incl. SIPLUS variants), SIMATIC S7-1500 CPU family (incl. related ET 200 CPUs and SIPLUS variants), SIMATIC S7-1500 Software Controller, SIMATIC S7-300 CPU 314C-2 PN/DP (6ES7314-6EH04-0AB0), SIMATIC S7-300 CPU 315-2 PN/DP (6ES7315-2EH14-0AB0), SIMATIC S7-300 CPU 315F-2 PN/DP (6ES7315-2FJ14-0AB0), SIMATIC S7-300 CPU 315T-3 PN/DP (6ES7315-7TJ10-0AB0), SIMATIC S7-300 CPU 317-2 PN/DP (6ES7317-2EK14-0AB0), SIMATIC S7-300 CPU 317F-2 PN/DP (6ES7317-2FK14-0AB0), SIMATIC S7-300 CPU 317T-3 PN/DP (6ES7317-7TK10-0AB0), SIMATIC S7-300 CPU 317TF-3 PN/DP (6ES7317-7UL10-0AB0), SIMATIC S7-300 CPU 319-3 PN/DP (6ES7318-3EL01-0AB0), SIMATIC S7-300 CPU 319F-3 PN/DP (6ES7318-3FL01-0AB0), SIMATIC S7-400 H V6 and below CPU family (incl. SIPLUS variants), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants), SIMATIC TDC CP51M1, SIMATIC TDC CPU555, SIMATIC WinAC RTX 2010 (6ES7671-0RC08-0YA0), SIMATIC WinAC RTX F 2010 (6ES7671-1RC08-0YA0), SINAMICS S/G Control Unit w. PROFINET, SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-2AC0), SIPLUS ET 200MP IM 155-5 PN HF (6AG1155-5AA00-7AC0), SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL (6AG2155-5AA00-1AC0), SIPLUS ET 200S IM 151-8 PN/DP CPU (6AG1151-8AB01-7AB0), SIPLUS ET 200S IM 151-8F PN/DP CPU (6AG1151-8FB01-2AB0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU00-2CN0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU00-4CN0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-2CN0), SIPLUS ET 200SP IM 155-6 PN HF (6AG1155-6AU01-7CN0), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU00-1CN0), SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL (6AG2155-6AU01-1CN0), SIPLUS ET 200SP IM 155-6 PN HF TX RAIL (6AG2155-6AU01-4CN0), SIPLUS NET PN/PN Coupler (6AG2158-3AD10-4XA0), SIPLUS S7-300 CPU 314C-2 PN/DP (6AG1314-6EH04-7AB0), SIPLUS S7-300 CPU 315-2 PN/DP (6AG1315-2EH14-7AB0), SIPLUS S7-300 CPU 315F-2 PN/DP (6AG1315-2FJ14-2AB0), SIPLUS S7-300 CPU 317-2 PN/DP (6AG1317-2EK14-7AB0), SIPLUS S7-300 CPU 317F-2 PN/DP (6AG1317-2FK14-2AB0). The Interniche-based TCP Stack can be forced to make very expensive calls for every incoming packet which can lead to a denial of service.


Published

2020-04-14T20:15:14.903

Last Modified

2025-07-08T11:15:22.140

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Secondary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens ktk_ate530s_firmware * Yes
Hardware siemens ktk_ate530s - No
Operating System siemens sidoor_atd430w_firmware * Yes
Hardware siemens sidoor_atd430w - No
Operating System siemens sidoor_ate530s_coated_firmware * Yes
Hardware siemens sidoor_ate530s_coated - No
Operating System siemens sidoor_ate531s_firmware * Yes
Hardware siemens sidoor_ate531s - No
Operating System siemens simatic_et_200sp_open_controller_cpu_1515sp_pc_firmware < 2.0 Yes
Hardware siemens simatic_et_200sp_open_controller_cpu_1515sp_pc - No
Operating System siemens simatic_et_200sp_open_controller_cpu_1515sp_pc2_firmware < 2.0 Yes
Hardware siemens simatic_et_200sp_open_controller_cpu_1515sp_pc2 - No
Operating System siemens simatic_et200mp_im155-5_pn_hf_firmware ≤ 4.2 Yes
Hardware siemens simatic_et200mp_im155-5_pn_hf - No
Operating System siemens simatic_et200sp_im155-6_mf_hf_firmware * Yes
Hardware siemens simatic_et200sp_im155-6_mf_hf - No
Operating System siemens simatic_et200sp_im155-6_pn_ha_firmware * Yes
Hardware siemens simatic_et200sp_im155-6_pn_ha - No
Operating System siemens simatic_et200sp_im155-6_pn_hf_firmware ≤ 4.2 Yes
Hardware siemens simatic_et200sp_im155-6_pn_hf - No
Operating System siemens simatic_et200sp_im155-6_pn\/2_hf_firmware ≤ 4.2 Yes
Hardware siemens simatic_et200sp_im155-6_pn\/2_hf - No
Operating System siemens simatic_et200sp_im155-6_pn\/2_hf_firmware ≤ 4.2 Yes
Hardware siemens simatic_et200sp_im155-6_pn\/2_hf - No
Operating System siemens simatic_micro-drive_pdc_firmware * Yes
Hardware siemens simatic_micro-drive_pdc - No
Operating System siemens simatic_pn\/pn_coupler_firmware ≤ 4.2 Yes
Hardware siemens simatic_pn\/pn_coupler - No
Operating System siemens simatic_s7-1500_cpu_1511-1_pn_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1511-1_pn - No
Operating System siemens simatic_s7-1500_cpu_1513-1_pn_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1513-1_pn - No
Operating System siemens simatic_s7-1500_cpu_1515-2_pn_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1515-2_pn - No
Operating System siemens simatic_s7-1500_cpu_1516-3_pn\/dp_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1516-3_pn\/dp - No
Operating System siemens simatic_s7-1500_cpu_1517-3_pn\/dp_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1517-3_pn\/dp - No
Operating System siemens simatic_s7-1500_cpu_1518-4_pn\/dp_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1518-4_pn\/dp - No
Operating System siemens simatic_s7-1500_cpu_1511f-1_pn_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1511f-1_pn - No
Operating System siemens simatic_s7-1500_cpu_1513f-1_pn_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1513f-1_pn - No
Operating System siemens simatic_s7-1500_cpu_1515f-2_pn_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1515f-2_pn - No
Operating System siemens simatic_s7-1500_cpu_1516f-3_pn\/dp_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1516f-3_pn\/dp - No
Operating System siemens simatic_s7-1500_cpu_1517f-3_pn\/dp_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1517f-3_pn\/dp - No
Operating System siemens simatic_s7-1500_cpu_1518f-4_pn\/dp_firmware < 2.0 Yes
Hardware siemens simatic_s7-1500_cpu_1518f-4_pn\/dp - No
Application siemens simatic_s7-1500 < 2.0 Yes
Operating System siemens simatic_s7-300_cpu_firmware * Yes
Hardware siemens simatic_s7-300_cpu - No
Operating System siemens simatic_s7-400_pn\/dp_firmware * Yes
Hardware siemens simatic_s7-400_pn\/dp v7 No
Operating System siemens simatic_s7-410_cpu_firmware * Yes
Hardware siemens simatic_s7-410_cpu - No
Operating System siemens simatic_tdc_cp51m1_firmware * Yes
Hardware siemens simatic_tdc_cp51m1 - No
Operating System siemens simatic_tdc_cpu555_firmware * Yes
Hardware siemens simatic_tdc_cpu555 - No
Operating System siemens simatic_winac_rtx_\(f\)_2010_firmware * Yes
Hardware siemens simatic_winac_rtx_\(f\)_2010 - No
Operating System siemens sinamics_s\/g_control_unit_firmware * Yes
Hardware siemens sinamics_s\/g_control_unit - No

References