Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2019-10936 |
CWE-ID | CWE-400 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
SINAMICS DCP Hardware solutions / Firmware SINAMICS SM120 Hardware solutions / Firmware SINAMICS SL150 Hardware solutions / Firmware SINAMICS S150 Hardware solutions / Firmware SINAMICS S120 Hardware solutions / Firmware SINAMICS S110 Hardware solutions / Firmware SINAMICS GM150 Hardware solutions / Firmware SINAMICS GL150 Hardware solutions / Firmware SINAMICS GH150 Hardware solutions / Firmware SINAMICS G150 Hardware solutions / Firmware SINAMICS G130 Hardware solutions / Firmware SINAMICS G120 Hardware solutions / Firmware SINAMICS G110M Hardware solutions / Firmware SINAMICS DCM Hardware solutions / Firmware SIMATIC WinAC RTX (F) 2010 Hardware solutions / Firmware SIMATIC S7-400H V6 Hardware solutions / Firmware SIMATIC S7-410 V8 Hardware solutions / Firmware SIMATIC S7-400 V6 Hardware solutions / Firmware SIMATIC S7-300 Hardware solutions / Firmware SIMATIC S7-1500 CPU Hardware solutions / Firmware SIMATIC S7-1200 Hardware solutions / Firmware SIMATIC PN/PN Coupler Hardware solutions / Firmware SIMATIC ET 200pro Hardware solutions / Firmware SIMATIC ET 200ecoPN Hardware solutions / Firmware IM 155-6 PN/3 HF Hardware solutions / Firmware IM 155-6 PN/2 HF Hardware solutions / Firmware IM 155-6 PN ST Hardware solutions / Firmware IM 155-6 PN HS Hardware solutions / Firmware IM 155-6 PN HF Hardware solutions / Firmware IM 155-6 PN HA Hardware solutions / Firmware IM 155-6 PN BA Hardware solutions / Firmware SIMATIC ET 200S Hardware solutions / Firmware IM 155-5 PN ST Hardware solutions / Firmware IM 155-5 PN HF Hardware solutions / Firmware IM 155-5 PN BA Hardware solutions / Firmware SIMATIC ET 200M Hardware solutions / Firmware SIMATIC ET 200AL Hardware solutions / Firmware SIMATIC CFU PA Hardware solutions / Firmware SINUMERIK 840D sl Server applications / SCADA systems SINUMERIK 828D Server applications / SCADA systems SIMATIC S7-400 PN/DP V7 Server applications / SCADA systems SIMATIC HMI KTP Mobile Panels Server applications / SCADA systems SIMATIC HMI Comfort Panels 4”-22” Server applications / SCADA systems SIMATIC HMI Comfort Outdoor Panels 7” & 15” Server applications / SCADA systems SIMATIC PROFINET Driver Hardware solutions / Drivers |
Vendor | Siemens |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU21936
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2019-10936
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper resource management when processing UDP packets. A remote attacker can send a large amount of specially crafted UDP packets, trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationSINAMICS DCP: All versions
SINUMERIK 840D sl: All versions
SINUMERIK 828D: All versions
SINAMICS SM120: All versions
SINAMICS SL150: All versions
SINAMICS S150: All versions
SINAMICS S120: All versions
SINAMICS S110: All versions
SINAMICS GM150: All versions
SINAMICS GL150: All versions
SINAMICS GH150: All versions
SINAMICS G150: All versions
SINAMICS G130: All versions
SINAMICS G120: All versions
SINAMICS G110M: All versions
SINAMICS DCM: All versions
SIMATIC WinAC RTX (F) 2010: All versions
SIMATIC S7-400H V6: All versions
SIMATIC S7-410 V8: All versions
SIMATIC S7-400 V6: All versions
SIMATIC S7-400 PN/DP V7: All versions
SIMATIC S7-300: All versions
SIMATIC S7-1500 CPU: 1.0 - 1.8
SIMATIC S7-1200: 2.00 - 4.2.3
SIMATIC PROFINET Driver: All versions
SIMATIC PN/PN Coupler: All versions
SIMATIC HMI KTP Mobile Panels: All versions
SIMATIC HMI Comfort Panels 4”-22”: All versions
SIMATIC HMI Comfort Outdoor Panels 7” & 15”: All versions
SIMATIC ET 200pro: All versions
SIMATIC ET 200ecoPN: All versions
IM 155-6 PN/3 HF: All versions
IM 155-6 PN/2 HF: All versions
IM 155-6 PN ST: All versions
IM 155-6 PN HS: All versions
IM 155-6 PN HF: All versions
IM 155-6 PN HA: All versions
IM 155-6 PN BA: All versions
SIMATIC ET 200S: All versions
IM 155-5 PN ST: All versions
IM 155-5 PN HF: All versions
IM 155-5 PN BA: All versions
SIMATIC ET 200M: All versions
SIMATIC ET 200AL: All versions
SIMATIC CFU PA: 1.0.1 - 1.1.2
CPE2.3https://cert-portal.siemens.com/productcert/pdf/ssa-473245.pdf
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.