CVE-2019-10925: High severity siemens simatic mv420 vulnerability
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by sending specially crafted requests to the integrated webserver. The security vulnerability can be exploited by an attacker with network access to the device. Valid user credentials, but no user interaction are required. Successful exploitation compromises integrity and availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10925?
CVE-2019-10925 is a vulnerability found in SIMATIC MV400 family (All Versions < V7.0.6) that allows an authenticated attacker to escalate privileges by sending specially crafted requests to the integrated webserver.
What is the severity of CVE-2019-10925?
CVE-2019-10925 has a severity rating of 7.1, which is considered high.
How can an attacker exploit CVE-2019-10925?
An attacker with network access to the device can exploit CVE-2019-10925 by sending specially crafted requests to the integrated webserver.
Which versions of SIMATIC MV400 family are affected by CVE-2019-10925?
All versions of SIMATIC MV400 family below V7.0.6 are affected by CVE-2019-10925.
Is Siemens Simatic Mv420 affected by CVE-2019-10925?
No, Siemens Simatic Mv420 is not affected by CVE-2019-10925.
Is Siemens Simatic Mv440 affected by CVE-2019-10925?
No, Siemens Simatic Mv440 is not affected by CVE-2019-10925.
How can I fix CVE-2019-10925?
To fix CVE-2019-10925, users should upgrade their SIMATIC MV400 family devices to version V7.0.6 or higher.