CVE-2019-6568
Last modified
CVE-2019-6568 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Cp1604 Firmware | All versions |
| Siemens | Cp1616 Firmware | All versions |
| Siemens | Simatic Rf185c Firmware | < 1.1.0 |
| Siemens | Simatic Cp343-1 Advanced Firmware | All versions |
| Siemens | Simatic Cp443-1 Firmware | All versions |
| Siemens | Simatic Cp443-1 Advanced Firmware | All versions |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515sp Pc Firmware | < 2.1.6 |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515sp Pc2 Firmware | < 2.7 |
| Siemens | Simatic Hmi Comfort Outdoor Panels Firmware | < 15.1 |
| Siemens | Simatic Hmi Comfort Outdoor Panels Firmware | 15.1 |
| Siemens | Simatic Hmi Comfort Panels Firmware | < 15.1 |
| Siemens | Simatic Hmi Comfort Panels Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp400f Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp400f Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700 Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700 Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700f Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp700f Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900 Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900 Firmware | 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900f Firmware | < 15.1 |
| Siemens | Simatic Hmi Ktp Mobile Panels Ktp900f Firmware | 15.1 |
| Siemens | Simatic Cp443-1 Opc Ua | All versions |
| Siemens | Simatic Ipc Diagmonitor | < 5.1.3 |
| Siemens | Simatic S7-1500 Software Controller | < 2.7 |
| Siemens | Simatic S7-Plcsim Advanced | < 2.0 |
| Siemens | Simatic S7-Plcsim Advanced | 2.0 |
| Siemens | Simatic Wincc Runtime Advanced | < 15.1 |
| Siemens | Simatic Wincc Runtime Advanced | 15.1 |
| Siemens | Sitop Manager | < 1.1 |
| Siemens | Simatic Rf600r Firmware | < 3.2.1 |
| Siemens | Simatic Rf188c Firmware | < 1.1.0 |
| Siemens | Simatic Rf186c Firmware | < 1.1.0 |
| Siemens | Simatic Rf182c Firmware | All versions |
| Siemens | Simatic Rf181-Eip Firmware | All versions |
| Siemens | Simatic S7-1500 Firmware | < 2.6.1 |
| Siemens | Simatic S7-300 Firmware | < 3.3.17 |
| Siemens | Simatic S7-400 Pn Firmware | All versions |
| Siemens | Simatic S7-400 Pn\/Dp Firmware | All versions |
| Siemens | Simatic Teleservice Adapter Ie Advanced Firmware | All versions |
| Siemens | Simatic Teleservice Adapter Ie Basic Firmware | All versions |
| Siemens | Simatic Teleservice Adapter Ie Standard Firmware | All versions |
| Siemens | Simatic Winac Rtx Firmware | < 2010 |
| Siemens | Simatic Winac Rtx Firmware | 2010 |
| Siemens | Simocode Pro V Eip Firmware | < 1.1.3 |
| Siemens | Simocode Pro V Pn Firmware | < 2.1.3 |
| Siemens | Sinamics G130 Firmware | < 5.2 |
| Siemens | Sinamics G150 Firmware | < 5.2 |
| Siemens | Sinamics S120 Firmware | < 5.2 |
| Siemens | Sinamics S150 Firmware | < 5.1 |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6568?
How severe is CVE-2019-6568?
How do I fix CVE-2019-6568?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6562In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, …5.4
- CVE-2019-6563Moxa IKS and EDS generate a predictable cookie calculated wi…9.8
- CVE-2019-6564GE Communicator, all versions prior to 4.0.517, allows a non…7.8
- CVE-2019-6565Moxa IKS and EDS fails to properly validate user input, givi…6.1
- CVE-2019-6566GE Communicator, all versions prior to 4.0.517, allows a non…7.8
- CVE-2019-6567A vulnerability has been identified in SCALANCE X-200 switch…5.5
- CVE-2019-6569The monitor barrier of the affected products insufficiently …9.1
- CVE-2019-6570A vulnerability has been identified in SINEMA Remote Connect…8.8
- CVE-2019-6571A vulnerability has been identified in SIEMENS LOGO!8 (6ED10…7.5
- CVE-2019-6572A vulnerability has been identified in SIMATIC HMI Comfort P…9.1
- CVE-2019-6574A vulnerability has been identified in SINAMICS PERFECT HARM…7.5
- CVE-2019-6575A vulnerability has been identified in SIMATIC CP 443-1 OPC …7.5
Are you affected by CVE-2019-6568?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
