SB2020011505 - Protection mechanism failure in Siemens SINAMICS PERFECT HARMONY GH180
Published: January 15, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Protection Mechanism Failure (CVE-ID: CVE-2019-19278)
The vulnerability allows a local attacker to restart the HMI with disabled security controls.
The vulnerability exists due to insufficient implementation of security measures. An attacker with physical access can restore the affected device to a point where predefined application and operating system protection mechanisms are not in place.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.