CVE-2019-6568

HIGHCVSS 7.5/10EPSS 1.40%

Last modified

CVE-2019-6568 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. EPSS estimates a 1.40% chance of exploitation in the next 30 days.

Description

The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.40%

69.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SiemensCp1604 FirmwareAll versions
SiemensCp1616 FirmwareAll versions
SiemensSimatic Rf185c Firmware< 1.1.0
SiemensSimatic Cp343-1 Advanced FirmwareAll versions
SiemensSimatic Cp443-1 FirmwareAll versions
SiemensSimatic Cp443-1 Advanced FirmwareAll versions
SiemensSimatic Et 200 Sp Open Controller Cpu 1515sp Pc Firmware< 2.1.6
SiemensSimatic Et 200 Sp Open Controller Cpu 1515sp Pc2 Firmware< 2.7
SiemensSimatic Hmi Comfort Outdoor Panels Firmware< 15.1
SiemensSimatic Hmi Comfort Outdoor Panels Firmware15.1
SiemensSimatic Hmi Comfort Panels Firmware< 15.1
SiemensSimatic Hmi Comfort Panels Firmware15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp400f Firmware< 15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp400f Firmware15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp700 Firmware< 15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp700 Firmware15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp700f Firmware< 15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp700f Firmware15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp900 Firmware< 15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp900 Firmware15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp900f Firmware< 15.1
SiemensSimatic Hmi Ktp Mobile Panels Ktp900f Firmware15.1
SiemensSimatic Cp443-1 Opc UaAll versions
SiemensSimatic Ipc Diagmonitor< 5.1.3
SiemensSimatic S7-1500 Software Controller< 2.7
SiemensSimatic S7-Plcsim Advanced< 2.0
SiemensSimatic S7-Plcsim Advanced2.0
SiemensSimatic Wincc Runtime Advanced< 15.1
SiemensSimatic Wincc Runtime Advanced15.1
SiemensSitop Manager< 1.1
SiemensSimatic Rf600r Firmware< 3.2.1
SiemensSimatic Rf188c Firmware< 1.1.0
SiemensSimatic Rf186c Firmware< 1.1.0
SiemensSimatic Rf182c FirmwareAll versions
SiemensSimatic Rf181-Eip FirmwareAll versions
SiemensSimatic S7-1500 Firmware< 2.6.1
SiemensSimatic S7-300 Firmware< 3.3.17
SiemensSimatic S7-400 Pn FirmwareAll versions
SiemensSimatic S7-400 Pn\/Dp FirmwareAll versions
SiemensSimatic Teleservice Adapter Ie Advanced FirmwareAll versions
SiemensSimatic Teleservice Adapter Ie Basic FirmwareAll versions
SiemensSimatic Teleservice Adapter Ie Standard FirmwareAll versions
SiemensSimatic Winac Rtx Firmware< 2010
SiemensSimatic Winac Rtx Firmware2010
SiemensSimocode Pro V Eip Firmware< 1.1.3
SiemensSimocode Pro V Pn Firmware< 2.1.3
SiemensSinamics G130 Firmware< 5.2
SiemensSinamics G150 Firmware< 5.2
SiemensSinamics S120 Firmware< 5.2
SiemensSinamics S150 Firmware< 5.1

Showing 50 of 71 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-6568?
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.
How severe is CVE-2019-6568?
CVE-2019-6568 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.40% probability of exploitation in the next 30 days.
How do I fix CVE-2019-6568?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-6568?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST