CVE-2019-10923

HIGHCVSS 7.5/10EPSS 1.40%

Last modified

CVE-2019-10923 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.

Description

An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.40%

69.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SiemensCp1604 Firmware< 2.8
SiemensCp1616 Firmware< 2.8
SiemensDk Standard Ethernet Controller Firmware< 4.1.1
SiemensDk Standard Ethernet Controller Firmware4.1.1
SiemensEk-Ertec 200 Firmware< 4.5.0
SiemensEk-Ertec 200 Firmware4.5.0
SiemensEk-Ertec 200p Firmware< 4.5.0
SiemensScalance X-200irt Firmware< 5.2.1
SiemensSimatic Et 200m FirmwareAll versions
SiemensSimatic Et 200s FirmwareAll versions
SiemensSimatic Et 200ecopn FirmwareAll versions
SiemensSimatic Pn\/Pn Coupler 6es7158-3ad01-0xa0 FirmwareAll versions
SiemensSimatic S7-300 Cpu Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 312 Ifm Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 313 Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 314 Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 314 Ifm Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 315 Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 315-2 Dp Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 316-2 Dp Firmware< 3.3.17
SiemensSimatic S7-300 Cpu 318-2 Firmware< 3.3.17
SiemensSimatic S7-400 V6 FirmwareAll versions
SiemensSimatic S7-400 Pn V7 FirmwareAll versions
SiemensSimatic S7-400 Dp V7 FirmwareAll versions
SiemensSimatic Winac Rtx \(F\) Firmware< 2010
SiemensSimatic Winac Rtx \(F\) Firmware2010
SiemensSimotion FirmwareAll versions
SiemensSinamics Dcm Firmware< 1.5
SiemensSinamics Dcm Firmware1.5
SiemensSinamics Dcp Firmware< 1.3
SiemensSinamics G110m Firmware< 4.7
SiemensSinamics G110m Firmware4.7
SiemensSinamics G120 Firmware< 4.7
SiemensSinamics G120 Firmware4.7
SiemensSinamics G130 Firmware< 4.7
SiemensSinamics G130 Firmware4.7
SiemensSinamics G150 Firmware< 4.8
SiemensSinamics Gh150 Firmware< 4.8
SiemensSinamics Gh150 Firmware4.8
SiemensSinamics Gl150 Firmware< 4.8
SiemensSinamics Gl150 Firmware4.8
SiemensSinamics Gm150 Firmware< 4.8
SiemensSinamics Gm150 Firmware4.8
SiemensSinamics S110 FirmwareAll versions
SiemensSinamics S120 Firmware< 4.7
SiemensSinamics S120 Firmware4.7
SiemensSinamics S150 Firmware< 4.8
SiemensSinamics Sl150 Firmware< 4.7
SiemensSinamics Sl150 Firmware4.7
SiemensSinamics Sm120 FirmwareAll versions

Showing 50 of 53 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10923?
An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.
How severe is CVE-2019-10923?
CVE-2019-10923 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.40% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10923?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10923?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST