CVE-2019-10938: Critical severity siemens siprotec 5 vulnerability
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1), Siemens Power Meters Series 9810 (All versions). An unauthenticated attacker with network access to the device could potentially insert arbitrary code which is executed before firmware verification in the device. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10938?
The severity of CVE-2019-10938 is critical with a CVSS score of 9.8.
How do I fix CVE-2019-10938?
To fix CVE-2019-10938, update SIPROTEC 5 devices to versions V7.59 for CP200 CPU variants, V8.01 for CP300 and CP100 CPU variants, V2.2.1 for Siemens Power Meters Series 9410, or the latest version for Siemens Power Meters Series 9810.
What is the vulnerability description of CVE-2019-10938?
CVE-2019-10938 is a vulnerability found in SIPROTEC 5 devices and Siemens Power Meters Series, allowing unauthorized access.
Are Siemens 6md85, 6md86, 6md89, 7sa82, 7sa86, 7sa87, 7sd82, 7sd86, 7sd87, 7sj82, 7sj85, 7sj86, 7sk82, 7sk85, 7sl82, 7sl86, 7sl87, 7um85, 7ut82, 7ut85, 7ut86, 7ut87, 7ve85, and 7vk87 affected by CVE-2019-10938?
No, Siemens 6md85, 6md86, 6md89, 7sa82, 7sa86, 7sa87, 7sd82, 7sd86, 7sd87, 7sj82, 7sj85, 7sj86, 7sk82, 7sk85, 7sl82, 7sl86, 7sl87, 7um85, 7ut82, 7ut85, 7ut86, 7ut87, 7ve85, and 7vk87 are not affected by CVE-2019-10938.
Where can I find more information about CVE-2019-10938?
More information about CVE-2019-10938 can be found in the Siemens product security advisories linked in the references.