CVE-2019-10936

Severity
7.5HIGH
EPSS
2.0%
top 16.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 24

Description

Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages138 packages

CVEListV5siemens/simatic_cfu_pa< V1.2.0
CVEListV5siemens/simatic_tdc_cp51m1< V1.1.8
CVEListV5siemens/simatic_tdc_cpu555< V1.1.1

🔴Vulnerability Details

2
GHSA
GHSA-vr9v-38cg-fjfp: A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller (All versions), Development/Evalua2022-05-24
CVEList
CVE-2019-10936: Affected devices improperly handle large amounts of specially crafted UDP packets2019-10-10
CVE-2019-10936 (HIGH CVSS 7.5) | Affected devices improperly handle | cvebase.io