Input validation error in DIGSI 5 and SIPROTEC 5 - CVE-2019-10931

 

Input validation error in DIGSI 5 and SIPROTEC 5 - CVE-2019-10931

Published: July 15, 2019


Vulnerability identifier: #VU19175
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-10931
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Siemens
Affected software:
DIGSI 5
SIPROTEC 5

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can use specially crafted packets sent to Port 443/TCP and cause a denial-of-service condition.

The vulnerability affects SIPROTEC 5 with CPU variants CP300 and CP100 and the respective Ethernet communication modules listed below:

  • 6MD85
  • 6MD86
  • 6MD89
  • 7UM85
  • 7SA87
  • 7SD87
  • 7SL87
  • 7VK87
  • 7SA82
  • 7SA86
  • 7SD82
  • 7SD86
  • 7SL82
  • 7SL86
  • 7SJ86
  • 7SK82
  • 7SK85
  • 7SJ82
  • 7SJ85
  • 7UT82
  • 7UT85
  • 7UT86
  • 7UT87
  • 7VE85

How to mitigate CVE-2019-10931

Install updates from vendor's website.

Sources