CVE-2019-10926: Medium severity siemens simatic mv420 vulnerability
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10926?
The severity of CVE-2019-10926 is medium.
Which versions of SIMATIC MV400 family are affected by CVE-2019-10926?
All versions of SIMATIC MV400 family below V7.0.6 are affected by CVE-2019-10926.
How does CVE-2019-10926 impact communication with the SIMATIC MV400 family device?
CVE-2019-10926 allows communication with the device to be intercepted by an attacker in a privileged network position.
Can the data transmitted between the SIMATIC MV400 family device and the user be obtained by an attacker?
Yes, an attacker in a privileged network position can obtain the data transmitted between the SIMATIC MV400 family device and the user.
How can the security vulnerability of CVE-2019-10926 be exploited?
CVE-2019-10926 can be exploited by an attacker in a privileged network position.