CVE-2019-13946
Last modified
CVE-2019-13946 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Dk Standard Ethernet Controller | All versions |
| Siemens | Profinet Driver | < 2.1 |
| Siemens | Simatic Ipc Support | All versions |
| Siemens | Ek-Ertec 200 Firmware | < 4.5 |
| Siemens | Ek-Ertec 200p Firmware | < 4.6 |
| Siemens | Ruggedcom Rm1224 Firmware | < 4.3 |
| Siemens | Scalance M-800 Firmware | < 4.3 |
| Siemens | Scalance S615 Firmware | < 4.3 |
| Siemens | Scalance W700 Ieee 802.11n Firmware | <= 6.0.1 |
| Siemens | Scalance Xc-200 Firmware | All versions |
| Siemens | Scalance Xf-200 Firmware | All versions |
| Siemens | Scalance Xp-200 Firmware | All versions |
| Siemens | Scalance Xb-200 Firmware | All versions |
| Siemens | Scalance X-200irt Firmware | < 5.3 |
| Siemens | Scalance Xr-300wg Firmware | < 3.0 |
| Siemens | Scalance X-300 Firmware | All versions |
| Siemens | Scalance Xb-200 Firmware | < 3.0 |
| Siemens | Scalance Xc-200 Firmware | < 3.0 |
| Siemens | Scalance Xp-200 Firmware | < 3.0 |
| Siemens | Scalance Xf-200ba Firmware | < 3.0 |
| Siemens | Scalance X-400 Firmware | < 6.0 |
| Siemens | Scalance Xm-400 Firmware | < 6.0 |
| Siemens | Scalance Xr524 Firmware | < 6.0 |
| Siemens | Scalance Xr526 Firmware | < 6.0 |
| Siemens | Scalance Xr528 Firmware | < 6.0 |
| Siemens | Scalance Xr552 Firmware | < 6.0 |
| Siemens | Simatic Cp 1616 Firmware | < 2.8 |
| Siemens | Simatic Cp 1604 Firmware | < 2.8 |
| Siemens | Simatic Cp 343-1 Firmware | All versions |
| Siemens | Simatic Cp 343-1 Advanced Firmware | All versions |
| Siemens | Simatic Cp 343-1 Erpc Firmware | All versions |
| Siemens | Simatic Cp 343-1 Lean Firmware | All versions |
| Siemens | Simatic Cp 443-1 Firmware | All versions |
| Siemens | Simatic Cp 443-1 Advanced Firmware | All versions |
| Siemens | Simatic Cp 443-1 Opc Ua Firmware | All versions |
| Siemens | Simatic Et200al Im 157-1 Pn Firmware | All versions |
| Siemens | Simatic Et200m Im153-4 Pn Io Hf Firmware | All versions |
| Siemens | Simatic Et200m Im153-4 Pn Io St Firmware | All versions |
| Siemens | Simatic Et200mp Im155-5 Pn Hf Firmware | < 4.2.0 |
| Siemens | Simatic Et200mp Im155-5 Pn St Firmware | < 4.1.0 |
| Siemens | Simatic Et200s Firmware | All versions |
| Siemens | Simatic Et200sp Im155-6 Pn Basic Firmware | All versions |
| Siemens | Simatic Et200sp Im155-6 Pn Hf Firmware | < 3.3.1 |
| Siemens | Simatic Et200sp Im155-6 Pn St Firmware | < 4.1.0 |
| Siemens | Simatic Et200ecopn Firmware | All versions |
| Siemens | Simatic Et200pro Firmware | All versions |
| Siemens | Im 154-3 Pn Hf Firmware | All versions |
| Siemens | Im 154-4 Pn Hf Firmware | All versions |
| Siemens | Simatic Mv440 Firmware | All versions |
| Siemens | Simatic Mv420 Firmware | All versions |
Showing 50 of 55 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13946?
How severe is CVE-2019-13946?
How do I fix CVE-2019-13946?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13940A vulnerability has been identified in SIMATIC ET 200pro IM1…7.5
- CVE-2019-13941A vulnerability has been identified in OZW672 (All versions …7.5
- CVE-2019-13942A vulnerability has been identified in EN100 Ethernet module…7.5
- CVE-2019-13943A vulnerability has been identified in EN100 Ethernet module…6.1
- CVE-2019-13944A vulnerability has been identified in EN100 Ethernet module…5.3
- CVE-2019-13945A vulnerability has been identified in SIMATIC S7-1200 CPU f…6.8
- CVE-2019-13947A vulnerability has been identified in Control Center Server…4.9
- CVE-2019-13948SyGuestBook A5 Version 1.2 allows stored XSS because the isV…
- CVE-2019-13949SyGuestBook A5 Version 1.2 has no CSRF protection mechanism,…
- CVE-2019-1395An elevation of privilege vulnerability exists in Windows wh…7.8
- CVE-2019-13950index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has …
- CVE-2019-13951The set_ipv4() function in zscan_rfc1035.rl in gdnsd 3.x bef…
Are you affected by CVE-2019-13946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
