7.8
CWE
400
Advisory Published
Updated

CVE-2019-13946

First published: Tue Feb 11 2020(Updated: )

Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.

Credit: productcert@siemens.com

Affected SoftwareAffected VersionHow to fix
Siemens Dk Standard Ethernet Controller
Siemens Profinet Driver<2.1
Siemens Simatic Ipc Support
Siemens Ek-ertec 200 Firmware<4.5
Siemens Ek-ertec 200
Siemens Ek-ertec 200p Firmware<4.6
Siemens Ek-ertec 200p
Siemens Ruggedcom Rm1224 Firmware<4.3
Siemens RUGGEDCOM RM1224
Siemens Scalance M-800 Firmware<4.3
Siemens SCALANCE M-800
Siemens Scalance S615 Firmware<4.3
Siemens SCALANCE S615
Siemens Scalance W700 Ieee 802.11n Firmware<=6.0.1
Siemens Scalance W700 Ieee 802.11n
Siemens Scalance Xc-200 Firmware
Siemens Scalance Xc-200
Siemens Scalance Xf-200 Firmware
Siemens Scalance Xf-200
Siemens Scalance Xp-200 Firmware
Siemens Scalance Xp-200
Siemens Scalance Xb-200 Firmware
Siemens Scalance Xb-200
Siemens Scalance X-200irt Firmware<5.3
Siemens Scalance X-200irt
Siemens Scalance Xr-300wg Firmware<3.0
Siemens Scalance Xr-300wg
Siemens Scalance X-300 Firmware
Siemens SCALANCE X-300
Siemens Scalance Xb-200 Firmware<3.0
Siemens Scalance Xc-200 Firmware<3.0
Siemens Scalance Xp-200 Firmware<3.0
Siemens Scalance Xf-200ba Firmware<3.0
Siemens Scalance Xf-200ba
Siemens Scalance X-400 Firmware<6.0
Siemens Scalance X-400
Siemens Scalance Xm-400 Firmware<6.0
Siemens Scalance Xm-400
Siemens Scalance Xr524 Firmware<6.0
Siemens Scalance Xr524
Siemens Scalance Xr526 Firmware<6.0
Siemens Scalance Xr526
Siemens Scalance Xr528 Firmware<6.0
Siemens Scalance Xr528
Siemens Scalance Xr552 Firmware<6.0
Siemens Scalance Xr552
Siemens Simatic Cp 1616 Firmware<2.8
Siemens Simatic Cp 1616
Siemens Simatic Cp 1604 Firmware<2.8
Siemens Simatic Cp 1604
Siemens Simatic Cp 343-1 Firmware
Siemens Simatic Cp 343-1
Siemens Simatic Cp 343-1 Advanced Firmware
Siemens Simatic Cp 343-1 Advanced
Siemens Simatic Cp 343-1 Erpc Firmware
Siemens Simatic Cp 343-1 Erpc
Siemens Simatic Cp 343-1 Lean Firmware
Siemens Simatic Cp 343-1 Lean
Siemens Simatic Cp 443-1 Firmware
Siemens Simatic Cp 443-1
Siemens Simatic Cp 443-1 Advanced Firmware
Siemens Simatic Cp 443-1 Advanced
Siemens Simatic Cp 443-1 Opc Ua Firmware
Siemens Simatic Cp 443-1 Opc Ua
Siemens Simatic Et200al Im 157-1 Pn Firmware
Siemens Simatic Et200al Im 157-1 Pn
Siemens Simatic Et200m Im153-4 Pn Io Hf Firmware
Siemens Simatic Et200m Im153-4 Pn Io Hf
Siemens Simatic Et200m Im153-4 Pn Io St Firmware
Siemens Simatic Et200m Im153-4 Pn Io St
Siemens Simatic Et200mp Im155-5 Pn Hf Firmware<4.2.0
Siemens Simatic Et200mp Im155-5 Pn Hf
Siemens Simatic Et200mp Im155-5 Pn St Firmware<4.1.0
Siemens Simatic Et200mp Im155-5 Pn St
Siemens Simatic Et200s Firmware
Siemens Simatic Et200s
Siemens Simatic Et200sp Im155-6 Pn Basic Firmware
Siemens Simatic Et200sp Im155-6 Pn Basic
Siemens Simatic Et200sp Im155-6 Pn Hf Firmware<3.3.1
Siemens Simatic Et200sp Im155-6 Pn Hf
Siemens Simatic Et200sp Im155-6 Pn St Firmware<4.1.0
Siemens Simatic Et200sp Im155-6 Pn St
Siemens Simatic Et200ecopn Firmware
Siemens Simatic Et200ecopn
Siemens Simatic Et200pro Firmware
Siemens Simatic Et200pro
Siemens Im 154-3 Pn Hf Firmware
Siemens Im 154-3 Pn Hf
Siemens Im 154-4 Pn Hf Firmware
Siemens Im 154-4 Pn Hf
Siemens Simatic Mv440 Firmware
Siemens Simatic Mv440
Siemens Simatic Mv420 Firmware
Siemens Simatic Mv420
Siemens Simatic Pn\/pn Coupler Firmware
Siemens Simatic Pn\/pn Coupler
Siemens Simatic Rf180c Firmware
Siemens Simatic Rf180c
Siemens Simatic Rf182c Firmware
Siemens Simatic Rf182c
Siemens Simatic Rf600 Firmware<3.0
Siemens Simatic Rf600
Siemens Sinamics Dcp Firmware<1.3
Siemens Sinamics Dcp

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203