CVE-2019-13939
published 2020-01-16CVE-2019-13939: A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions = V2.8.2 = V2.8.2 = V2.3 = V2.3x and = V2.3 = V2.3 = V2.3 = V2.3x and = V2.3 =…
PriorityP431high7.1CVSS 3.1
AVAACLPRNUINSUCNILAH
EPSS
0.71%
49.6th percentile
A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions = V2.8.2 = V2.8.2 = V2.3 = V2.3x and = V2.3 = V2.3 = V2.3 = V2.3x and = V2.3 = V2.3 = V2.3 = V2.3 = V2.3 = V2.3x and = V2.3 < V6.0.327), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus Source Code (All versions), SIMOTICS CONNECT 400 (All versions < V0.3.0.330), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). By sending specially crafted DHCP packets to a device where the DHCP client is enabled, an attacker could change the IP address of the device to an invalid value.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | apogee_mec_mbc_pxc | — | — |
| siemens | apogee_modular_building_controller_firmware | < 2.8.2 | 2.8.2 |
| siemens | apogee_modular_equiment_controller_firmware | < 2.8.2 | 2.8.2 |
| siemens | apogee_pxc_compact | < V3.5.3 | V3.5.3 |
| siemens | apogee_pxc_compact | >= V2.8.2 < V2.8.19 | V2.8.19 |
| siemens | apogee_pxc_firmware | <= 2.8.2 | — |
| siemens | apogee_pxc_modular | < V3.5.3 | V3.5.3 |
| siemens | apogee_pxc_modular | >= V2.8.2 < V2.8.19 | V2.8.19 |
| siemens | capital_embedded_ar_classic_431-422 | < * | * |
| siemens | capital_embedded_ar_classic_r20-11 | < V2303 | V2303 |
| siemens | desigo_pxc00-e.d | >= V2.3 < V6.0.327 | V6.0.327 |
| siemens | desigo_pxc00-e.d_firmware | >= 2.3.0 < 6.00.327 | 6.00.327 |
| siemens | desigo_pxc00-u | — | — |
| siemens | desigo_pxc00-u_firmware | >= 2.3.0 < 6.00.327 | 6.00.327 |
| siemens | desigo_pxc001-e.d | >= V2.3 < V6.0.327 | V6.0.327 |
| siemens | desigo_pxc001-e.d_firmware | >= 2.3.0 < 6.00.327 | 6.00.327 |
| siemens | desigo_pxc100-e.d | >= V2.3 < V6.0.327 | V6.0.327 |
| siemens | desigo_pxc12-e.d | >= V2.3 < V6.0.327 | V6.0.327 |
| siemens | desigo_pxc12-e.d_firmware | >= 2.3.0 < 6.00.327 | 6.00.327 |
| siemens | desigo_pxc128-u | — | — |
| siemens | desigo_pxc200-e.d | >= V2.3 < V6.0.327 | V6.0.327 |
| siemens | desigo_pxc22-e.d | >= V2.3 < V6.0.327 | V6.0.327 |
| siemens | desigo_pxc22-e.d_firmware | >= 2.3.0 < 6.00.327 | 6.00.327 |
| siemens | desigo_pxc22.1-e.d | >= V2.3 < V6.0.327 | V6.0.327 |
| siemens | desigo_pxc22.1-e.d_firmware | >= 2.3.0 < 6.00.327 | 6.00.327 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update D)
cisa_ics·2021-04-14
Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update D)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update D)
Last RevisedMay 12, 2022
Alert CodeICSA-20-105-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.1
- ATTENTION: Exploitable from an adjacent network/low skill level to exploit
- Vendor: Siemens
- Equipment: SIMOTICS, Desigo, APOGEE, and TALON
- Vulnerability: Business Logic Errors
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-20-105-06 Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update C) that was published April 14, 2021, on the ICS webpage at cisa.gov/ics.
## 3. RISK EVALUATI
CISA ICS
Siemens Mentor Nucleus Networking Module
cisa_ics·2019-11-14·CVSS 7.1
[HIGH] Siemens Mentor Nucleus Networking Module
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Mentor Nucleus Networking Module
Last RevisedNovember 14, 2019
Alert CodeICSA-19-318-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.1
- ATTENTION: Low skill level to exploit
- Vendor: Siemens
- Equipment: Mentor Nucleus Networking Module
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to affect the integrity and availability of the device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following networking modules from Mentor Nucleus (a division of Siemens) are affected:
- Nucl
GHSA
GHSA-jpvr-c9fc-2r4h: A vulnerability has been identified in Nucleus NET (All versions), Nucleus RTOS (All versions), Nucleus ReadyStart for ARM, MIPS, and PPC (All version
ghsa_unreviewed·2022-05-24
CVE-2019-13939 [MEDIUM] CWE-20 GHSA-jpvr-c9fc-2r4h: A vulnerability has been identified in Nucleus NET (All versions), Nucleus RTOS (All versions), Nucleus ReadyStart for ARM, MIPS, and PPC (All version
A vulnerability has been identified in Nucleus NET (All versions), Nucleus RTOS (All versions), Nucleus ReadyStart for ARM, MIPS, and PPC (All versions < V2017.02.2 with patch "Nucleus 2017.02.02 Nucleus NET Patch"), Nucleus SafetyCert (All versions), Nucleus Source Code (All versions), VSTAR (All versions). By sending specially crafted DHCP packets to a device, an attacker may be able to affect availability and integrity of the device. Adjacent network access, but no authentication and no user interaction is needed to conduct this attack. At the time of advisory publication no public exploitation of this security vulnerability was known.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/html/ssa-162506.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-434032.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-162506.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-434032.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-20-105-06https://cert-portal.siemens.com/productcert/html/ssa-162506.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-434032.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-162506.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-434032.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-20-105-06
2020-01-16
Published