CVE-2019-6568
Last modified
CVE-2019-6568 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Cp1604 Firmware | All versions |
| Siemens | Cp1616 Firmware | All versions |
| Siemens | Simatic Rf185c Firmware | < 1.1.0 |
| Siemens | Simatic Cp343-1 Advanced Firmware | All versions |
| Siemens | Simatic Cp443-1 Firmware | All versions |
| Siemens | Simatic Cp443-1 Advanced Firmware | All versions |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515sp Pc Firmware | < 2.1.6 |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515sp Pc2 Firmware | < 2.7 |
| Siemens | Simatic Hmi Comfort Outdoor Panels Firmware | < 15.1 |
| Siemens | Simatic Hmi Comfort Outdoor Panels Firmware | 15.1 |
| Siemens | Simatic Hmi Comfort Panels Firmware | < 15.1 |
| Siemens | Simatic Hmi Comfort Panels Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp400f Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp400f Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700 Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700 Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700f Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700f Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900 Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900 Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900f Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900f Firmware | 15.1 |
| Siemens | Simatic Cp443-1 Opc Ua | All versions |
| Siemens | Simatic Ipc Diagmonitor | < 5.1.3 |
| Siemens | Simatic S7-1500 Software Controller | < 2.7 |
| Siemens | Simatic S7-Plcsim Advanced | < 2.0 |
| Siemens | Simatic S7-Plcsim Advanced | 2.0 |
| Siemens | Simatic Wincc Runtime Advanced | < 15.1 |
| Siemens | Simatic Wincc Runtime Advanced | 15.1 |
| Siemens | Sitop Manager | < 1.1 |
| Siemens | Simatic Rf600r Firmware | < 3.2.1 |
| Siemens | Simatic Rf188c Firmware | < 1.1.0 |
| Siemens | Simatic Rf186c Firmware | < 1.1.0 |
| Siemens | Simatic Rf182c Firmware | All versions |
| Siemens | Simatic Rf181-Eip Firmware | All versions |
| Siemens | Simatic S7-1500 Firmware | < 2.6.1 |
| Siemens | Simatic S7-300 Firmware | < 3.3.17 |
| Siemens | Simatic S7-400 Pn Firmware | All versions |
| Siemens | Simatic S7-400 Pn\/Dp Firmware | All versions |
| Siemens | Simatic Teleservice Adapter Ie Advanced Firmware | All versions |
| Siemens | Simatic Teleservice Adapter Ie Basic Firmware | All versions |
| Siemens | Simatic Teleservice Adapter Ie Standard Firmware | All versions |
| Siemens | Simatic Winac Rtx Firmware | < 2010 |
| Siemens | Simatic Winac Rtx Firmware | 2010 |
| Siemens | Simocode Pro V Eip Firmware | < 1.1.3 |
| Siemens | Simocode Pro V Pn Firmware | < 2.1.3 |
| Siemens | Sinamics G130 Firmware | < 5.2 |
| Siemens | Sinamics G150 Firmware | < 5.2 |
| Siemens | Sinamics S120 Firmware | < 5.2 |
| Siemens | Sinamics S150 Firmware | < 5.1 |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6568?
How severe is CVE-2019-6568?
How do I fix CVE-2019-6568?
Are you affected by CVE-2019-6568?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
