CVE-2019-13926: High severity siemens scalance s602 firmware vulnerability
A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port 443/tcp of affected devices could cause a Denial-of-Service condition of the web server. A cold reboot is required to restore the functionality of the device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-13926.
Which devices are affected by this vulnerability?
The SCALANCE S602, SCALANCE S612, SCALANCE S623, and SCALANCE S627-2M devices with firmware versions >= V3.0 and < V4.1 are affected by this vulnerability.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is high with a CVSS score of 7.5.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending specially crafted packets to port 443/tcp of the affected devices.
Is there a fix available for this vulnerability?
Siemens has released firmware updates to address this vulnerability. Please refer to the product advisories for more information.