CVE-2019-19282
published 2020-03-10CVE-2019-19282: A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.31%
67.4th percentile
A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (All versions < V8.2 Upd12), SIMATIC BATCH V9.0 (All versions < V9.0 SP1 Upd5), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Update 1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC Route Control V8.1 (All versions), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions < V9.0 Upd4), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC (TIA Portal) V15.1 (All versions < V15.1 Update 5), SIMATIC WinCC (TIA Portal) V16 (All versions < V16 Update 1), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 1). Through specially crafted messages, when encrypted communication is enabled, an attacker with network access could use the vulnerability to compromise the availability of the system by causing a Denial-of-Service condition.
Successful exploitation requires no system privileges and no user interaction.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | openpcs_7 | — | — |
| siemens | openpcs_7 | — | — |
| siemens | openpcs_7_v8.1 | — | — |
| siemens | openpcs_7_v8.2 | — | — |
| siemens | openpcs_7_v9.0 | — | — |
| siemens | simatic_batch | — | — |
| siemens | simatic_batch_v8.1 | — | — |
| siemens | simatic_batch_v8.2 | — | — |
| siemens | simatic_batch_v9.0 | — | — |
| siemens | simatic_net_pc | < 16 | 16 |
| siemens | simatic_net_pc | — | — |
| siemens | simatic_net_pc_software_v14 | — | — |
| siemens | simatic_net_pc_software_v15 | — | — |
| siemens | simatic_net_pc_software_v16 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7_v8.1 | — | — |
| siemens | simatic_pcs_7_v8.2 | — | — |
| siemens | simatic_pcs_7_v9.0 | — | — |
| siemens | simatic_route_control | < 9.0 | 9.0 |
| siemens | simatic_route_control | — | — |
| siemens | simatic_route_control_v8.1 | — | — |
| siemens | simatic_route_control_v8.2 | — | — |
| siemens | simatic_route_control_v9.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC (Update G)
cisa_ics·2021-01-12
Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC (Update G)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC (Update G)
Last RevisedApril 14, 2022
Alert CodeICSA-20-042-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SIMATIC PCS 7, SIMATIC WinCC, SIMATIC NET PC
- Vulnerability: Incorrect Calculation of Buffer Size
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled 20-042-06 Siemens SIMATIC PCS 7, SIMATIC WinCC, and SIMATIC NET PC (Update F) that was published January 12, 2021, on the ICS webpage on w
GHSA
GHSA-2pg9-8888-cqmc: A vulnerability has been identified in OpenPCS 7 V8
ghsa_unreviewed·2022-05-24
CVE-2019-19282 [HIGH] CWE-131 GHSA-2pg9-8888-cqmc: A vulnerability has been identified in OpenPCS 7 V8
A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (All versions), SIMATIC BATCH V9.0 (All versions), SIMATIC NET PC Software (All versions < V16 update 1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC Route Control V8.1 (All versions), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14.0.1 (All versions), SIMATIC WinCC (TIA Portal) V15.1 (All versions), SIMATIC WinCC (TIA Portal) V16 (All versions), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions),
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-10
Published