cbcvebase.
CVE-2019-10953
published 2019-04-17

CVE-2019-10953: ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.67%
88.4th percentile
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

Affected

10 ranges
VendorProductVersion rangeFixed in
abb1sap120600r0071_pm554-tp-eth
phoenix_contact2700974_ilc_151_eth
phoenix_contactilc_191_eth_2tx
schneider-electricmodicon_m221_firmware< 1.10.0.01.10.0.0
schneider_electricecostruxure_machine_expert_basic< v1.0v1.0
schneider_electricmodicon_m221< v1.10.0.0v1.10.0.0
wago750-8100_controller_pfc100
wago750-831_controller_bacnet_ip
wago750-880_controller_eth
wago750-889_controller_knx_ip

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.