CVE-2019-13946
published 2020-02-11CVE-2019-13946: Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.45%
70.4th percentile
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit
internal resource allocation when multiple legitimate diagnostic package
requests are sent to the DCE-RPC interface.
This could lead to a denial of service condition due to lack of memory
for devices that include a vulnerable version of the stack.
The security vulnerability could be exploited by an attacker with network
access to an affected device. Successful exploitation requires no system
privileges and no user interaction. An attacker could use the vulnerability
to compromise the availability of the device.
Affected
149 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | development_evaluation_kits_for_profinet_io_dk_standard_ethernet_controller | < * | * |
| siemens | development_evaluation_kits_for_profinet_io_ek-ertec_200 | — | — |
| siemens | development_evaluation_kits_for_profinet_io_ek-ertec_200p | — | — |
| siemens | ek-ertec_200_firmware | < 4.5 | 4.5 |
| siemens | ek-ertec_200p_firmware | < 4.6 | 4.6 |
| siemens | profinet_driver | < 2.1 | 2.1 |
| siemens | profinet_driver_for_controller | — | — |
| siemens | ruggedcom_rm1224_family | — | — |
| siemens | ruggedcom_rm1224_firmware | < 4.3 | 4.3 |
| siemens | scalance_m-800_firmware | < 4.3 | 4.3 |
| siemens | scalance_m804pb | — | — |
| siemens | scalance_m812-1_adsl-router | — | — |
| siemens | scalance_m816-1_adsl-router | — | — |
| siemens | scalance_m826-2_shdsl-router | — | — |
| siemens | scalance_m874-2 | — | — |
| siemens | scalance_m874-3 | — | — |
| siemens | scalance_m876-3 | — | — |
| siemens | scalance_m876-4 | — | — |
| siemens | scalance_s615_firmware | < 4.3 | 4.3 |
| siemens | scalance_s615_lan-router | — | — |
| siemens | scalance_w-700_ieee_802.11n_family | — | — |
| siemens | scalance_w700_ieee_802.11n_firmware | <= 6.0.1 | — |
| siemens | scalance_x-200irt_firmware | < 5.3 | 5.3 |
| siemens | scalance_x-400_firmware | < 6.0 | 6.0 |
| siemens | scalance_x200-4p_irt | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
ghsa5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8fqx-3qjr-87gw: A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller (All versions), Development/Evalua
ghsa_unreviewed·2022-05-24
CVE-2019-13946 [HIGH] CWE-400 GHSA-8fqx-3qjr-87gw: A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller (All versions), Development/Evalua
A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller (All versions), Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200 (All Versions < V4.5), Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P (All Versions < V4.6), PROFINET Driver for Controller (All Versions < V2.1), RUGGEDCOM RM1224 (All versions < V4.3), SCALANCE M-800 / S615 (All versions < V4.3), SCALANCE W700 IEEE 802.11n (All versions <= V6.0.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All Versions < V5.3), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions), SCALANCE XB-200, XC-200, XP-200, XF-200BA and XR-300WG (All Versions < V3.0
GHSA
Man-in-the-middle attack in Apache Cassandra
ghsa·2021-05-07·CVSS 5.9
CVE-2020-13946 [MEDIUM] CWE-668 Man-in-the-middle attack in Apache Cassandra
Man-in-the-middle attack in Apache Cassandra
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.
CISA ICS
Siemens PROFINET-IO Stack (Update H)
cisa_ics·2022-04-14
Siemens PROFINET-IO Stack (Update H)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens PROFINET-IO Stack (Update H)
Last RevisedJune 16, 2022
Alert CodeICSA-20-042-04
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Siemens PROFINET-IO Stack
- Vulnerability: Uncont
Red Hat
cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface
vendor_redhat·2020-09-01·CVSS 5.9
CVE-2020-13946 [MEDIUM] CWE-200 cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface
cassandra: allows manipulation of the RMI registry to perform a MITM attack and capture user names and passwords used to access the JMX interface
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.
A flaw was found in cassandra in versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-bet
No detection rules found.
No public exploits indexed.
2020-02-11
Published