CVE-2019-6568
published 2019-04-17CVE-2019-6568: The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.40%
69.4th percentile
The webserver of the affected devices contains a vulnerability that may lead to
a denial of service condition. An attacker may cause a denial of service
situation which leads to a restart of the webserver of the affected device.
The security vulnerability could be exploited by an attacker with network
access to the affected systems. Successful exploitation requires no system
privileges and no user interaction. An attacker could use the vulnerability
to compromise availability of the device.
Affected
154 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| siemens | simatic_cp_1604 | — | — |
| siemens | simatic_cp_1616 | — | — |
| siemens | simatic_cp_343-1_advanced | — | — |
| siemens | simatic_cp_443-1 | — | — |
| siemens | simatic_cp_443-1_advanced | — | — |
| siemens | simatic_cp_443-1_opc_ua | — | — |
| siemens | simatic_et_200_sp_open_controller_cpu_1515sp_pc2_firmware | < 2.7 | 2.7 |
| siemens | simatic_et_200_sp_open_controller_cpu_1515sp_pc_firmware | < 2.1.6 | 2.1.6 |
| siemens | simatic_et_200pro_im154-8_pn_dp_cpu | — | — |
| siemens | simatic_et_200pro_im154-8f_pn_dp_cpu | — | — |
| siemens | simatic_et_200pro_im154-8fx_pn_dp_cpu | — | — |
| siemens | simatic_et_200s_im151-8_pn_dp_cpu | — | — |
| siemens | simatic_et_200s_im151-8f_pn_dp_cpu | — | — |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc | — | — |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc2 | — | — |
| siemens | simatic_hmi_comfort_outdoor_panels_7_15 | — | — |
| siemens | simatic_hmi_comfort_outdoor_panels_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_comfort_outdoor_panels_firmware | — | — |
| siemens | simatic_hmi_comfort_panels_4_22 | — | — |
| siemens | simatic_hmi_comfort_panels_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_comfort_panels_firmware | — | — |
| siemens | simatic_hmi_ktp_mobile_panels_ktp400f_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_ktp_mobile_panels_ktp400f_firmware | — | — |
| siemens | simatic_hmi_ktp_mobile_panels_ktp700_firmware | < 15.1 | 15.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2020-6566
vendor_chrome·2020-08-25·CVSS 6.5
CVE-2020-6566 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6566
Stable Channel Update for Desktop
CVE-2020-6566: Insufficient policy enforcement in media. Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2020-03-27 [$500][ 937179 ] Low CVE-2020-6567: Insufficient validation of untrusted input in command line handling
Reported by Joshua Graham of TSS on 2019-03-01 [$500][ 1092451 ] Low CVE-2020-6568: Insufficient policy enforcement in intent handling
Severity: medium
CISA ICS
Siemens SIMATIC, SIMOCODE, SINAMICS, SITOP, and TIM (Update I)
cisa_ics·2020-06-09
Siemens SIMATIC, SIMOCODE, SINAMICS, SITOP, and TIM (Update I)
ICS Advisory
##
Siemens SIMATIC, SIMOCODE, SINAMICS, SITOP, and TIM (Update I)
Last RevisedJanuary 13, 2023
Alert CodeICSA-19-099-06
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SIMATIC, SIMOCODE, SINAMICS, SITOP, and TIM
- Vulnerability: Out-of-bounds Read
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the updated advisory titled ICSA-19-099-06 Si
CISA ICS
Siemens SINAMICS (Update C)
cisa_ics·2019-12-10
Siemens SINAMICS (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINAMICS (Update C)
Last RevisedMay 12, 2020
Alert CodeICSA-19-227-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SINAMICS
- Vulnerability: Uncontrolled Resource Consumption
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update ICSA-19-227-04 Siemens SINAMICS (Update B) that was published December 10, 2019, to the ICS webpage on us-cert.gov.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability may allow an attacker to perform a denia
GHSA
GHSA-gm8r-2vc4-2wvx: A vulnerability has been identified in RFID 181EIP, SIMATIC CP 1604, SIMATIC CP 1616, SIMATIC CP 343-1 Advanced, SIMATIC CP 443-1, SIMATIC CP 443-1 Ad
ghsa_unreviewed·2022-05-13
CVE-2019-6568 [HIGH] CWE-125 GHSA-gm8r-2vc4-2wvx: A vulnerability has been identified in RFID 181EIP, SIMATIC CP 1604, SIMATIC CP 1616, SIMATIC CP 343-1 Advanced, SIMATIC CP 443-1, SIMATIC CP 443-1 Ad
A vulnerability has been identified in RFID 181EIP, SIMATIC CP 1604, SIMATIC CP 1616, SIMATIC CP 343-1 Advanced, SIMATIC CP 443-1, SIMATIC CP 443-1 Advanced, SIMATIC CP 443-1 OPC UA, SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants), SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F, SIMATIC IPC DiagMonitor, SIMATIC RF182C, SIMATIC RF185C, SIMATIC RF186C, SIMATIC RF188C, SIMATIC RF600 family, SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants), SIMATIC S7-1500 Software Controller, SIMATIC S7-300 CPU family (incl. related ET
No detection rules found.
No public exploits indexed.
2019-04-17
Published