7.5
CVSSv3

CVE-2019-13946

Published: 11/02/2020 Updated: 11/04/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens profinet driver

siemens dk standard ethernet controller

siemens simatic ipc support

siemens ek-ertec 200 firmware

siemens ek-ertec 200p firmware

siemens ruggedcom rm1224 firmware

siemens scalance m-800 firmware

siemens scalance s615 firmware

siemens scalance w700 ieee 802.11n firmware

siemens scalance xc-200 firmware

siemens scalance xf-200 firmware

siemens scalance xp-200 firmware

siemens scalance xb-200 firmware

siemens scalance x-200irt firmware

siemens scalance xr-300wg firmware

siemens scalance x-300 firmware

siemens scalance xf-200ba firmware

siemens scalance x-400 firmware

siemens scalance xm-400 firmware

siemens scalance xr524 firmware

siemens scalance xr526 firmware

siemens scalance xr528 firmware

siemens scalance xr552 firmware

siemens simatic cp 1616 firmware

siemens simatic cp 1604 firmware

siemens simatic cp 343-1 firmware

siemens simatic cp 343-1 advanced firmware

siemens simatic cp 343-1 erpc firmware

siemens simatic cp 343-1 lean firmware

siemens simatic cp 443-1 firmware

siemens simatic cp 443-1 advanced firmware

siemens simatic cp 443-1 opc ua firmware

siemens simatic et200al im 157-1 pn firmware

siemens simatic et200m im153-4 pn io hf firmware

siemens simatic et200m im153-4 pn io st firmware

siemens simatic et200mp im155-5 pn hf firmware

siemens simatic et200mp im155-5 pn st firmware

siemens simatic et200s firmware

siemens simatic et200sp im155-6 pn basic firmware

siemens simatic et200sp im155-6 pn hf firmware

siemens simatic et200sp im155-6 pn st firmware

siemens simatic et200ecopn firmware

siemens simatic et200pro firmware

siemens im 154-3 pn hf firmware

siemens im 154-4 pn hf firmware

siemens simatic mv440 firmware

siemens simatic mv420 firmware

siemens simatic pn/pn coupler firmware

siemens simatic rf180c firmware

siemens simatic rf182c firmware

siemens simatic rf600 firmware

siemens sinamics dcp firmware

ICS Advisories