CVE-2019-19301
published 2020-04-14CVE-2019-19301: A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT, SCALANCE…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.33%
67.7th percentile
A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT, SCALANCE X202-2P IRT PRO, SCALANCE X204-2, SCALANCE X204-2FM, SCALANCE X204-2LD, SCALANCE X204-2LD TS, SCALANCE X204-2TS, SCALANCE X204IRT, SCALANCE X204IRT PRO, SCALANCE X206-1, SCALANCE X206-1LD, SCALANCE X208, SCALANCE X208PRO, SCALANCE X212-2, SCALANCE X212-2LD, SCALANCE X216, SCALANCE X224, SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (2x 230V, coated), SCALANCE X307-2 EEC (2x 230V), SCALANCE X307-2 EEC (2x 24V, coated), SCALANCE X307-2 EEC (2x 24V), SCALANCE X307-3, SCALANCE X307-3, SCALANCE X307-3LD, SCALANCE X307-3LD, SCALANCE X308-2, SCALANCE X308-2, SCALANCE X308-2LD, SCALANCE X308-2LD, SCALANCE X308-2LH, SCALANCE X308-2LH, SCALANCE X308-2LH+, SCALANCE X308-2LH+, SCALANCE X308-2M, SCALANCE X308-2M, SCALANCE X308-2M PoE, SCALANCE X308-2M PoE, SCALANCE X308-2M TS, SCALANCE X308-2M TS, SCALANCE X310, SCALANCE X310, SCALANCE X310FE, SCALANCE X310FE, SCALANCE X320-1 FE, SCALANCE X320-1-2LD FE, SCALANCE X408-2, SCALANCE XF201-3P IRT, SCALANCE XF202-2P IRT, SCALANCE XF204, SCALANCE XF204-2, SCALANCE XF204-2BA IRT, SCALANCE XF204IRT, SCALANCE XF206-1, SCALANCE XF208, SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M TS
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | scalance_x-200irt_firmware | < 5.5.0 | 5.5.0 |
| siemens | scalance_x200-4p_irt | — | — |
| siemens | scalance_x201-3p_irt | — | — |
| siemens | scalance_x201-3p_irt_pro | — | — |
| siemens | scalance_x202-2irt | — | — |
| siemens | scalance_x202-2p_irt | — | — |
| siemens | scalance_x202-2p_irt_pro | — | — |
| siemens | scalance_x204-2 | — | — |
| siemens | scalance_x204-2fm | — | — |
| siemens | scalance_x204-2ld | — | — |
| siemens | scalance_x204-2ld_ts | — | — |
| siemens | scalance_x204-2ts | — | — |
| siemens | scalance_x204irt | — | — |
| siemens | scalance_x204irt_pro | — | — |
| siemens | scalance_x206-1 | — | — |
| siemens | scalance_x206-1ld | — | — |
| siemens | scalance_x208 | — | — |
| siemens | scalance_x208pro | — | — |
| siemens | scalance_x212-2 | — | — |
| siemens | scalance_x212-2ld | — | — |
| siemens | scalance_x216 | — | — |
| siemens | scalance_x224 | — | — |
| siemens | scalance_x302-7_eec | — | — |
| siemens | scalance_x304-2fe | — | — |
| siemens | scalance_x306-1ld_fe | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE and SIMATIC (Update H)
cisa_ics·2022-04-14
Siemens SCALANCE and SIMATIC (Update H)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE and SIMATIC (Update H)
Last RevisedMay 12, 2022
Alert CodeICSA-20-105-07
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE, SIMATIC
- Vulnerability: Resource Exhaustion
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-20-105-07 Siemens SCALANCE & SIMATIC (Update G) that was published April 14, 2022, to the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability can result in a denial-
GHSA
GHSA-j5jq-7977-4wm2: A vulnerability has been identified in SCALANCE X-200 switch family (incl
ghsa_unreviewed·2022-05-24
CVE-2019-19301 [MEDIUM] CWE-400 GHSA-j5jq-7977-4wm2: A vulnerability has been identified in SCALANCE X-200 switch family (incl
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions), SIMATIC CP 443-1 (incl. SIPLUS NET variants) (All versions), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variants) (All versions), SIMATIC RF180C (All versions), SIMATIC RF182C (All versions). The VxWorks-based Profinet TCP Stack can be forced to make very expensive calls for every incoming packet which can lead to a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-14
Published