CVE-2019-6569
published 2019-03-26CVE-2019-6569: The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could…
PriorityP346critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.33%
67.7th percentile
The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| siemens | scalance_x-200_firmware | < 5.2.4 | 5.2.4 |
| siemens | scalance_x-300_firmware | < 4.1.3 | 4.1.3 |
| siemens | scalance_x204-2 | — | — |
| siemens | scalance_x204-2fm | — | — |
| siemens | scalance_x204-2ld | — | — |
| siemens | scalance_x204-2ld_ts | — | — |
| siemens | scalance_x204-2ts | — | — |
| siemens | scalance_x206-1 | — | — |
| siemens | scalance_x206-1ld | — | — |
| siemens | scalance_x208 | — | — |
| siemens | scalance_x208pro | — | — |
| siemens | scalance_x212-2 | — | — |
| siemens | scalance_x212-2ld | — | — |
| siemens | scalance_x216 | — | — |
| siemens | scalance_x224 | — | — |
| siemens | scalance_x302-7_eec | — | — |
| siemens | scalance_x304-2fe | — | — |
| siemens | scalance_x306-1ld_fe | — | — |
| siemens | scalance_x307-2_eec | — | — |
| siemens | scalance_x307-3 | — | — |
| siemens | scalance_x307-3ld | — | — |
| siemens | scalance_x308-2 | — | — |
| siemens | scalance_x308-2ld | — | — |
| siemens | scalance_x308-2lh | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE X (Update D)
cisa_ics·2021-10-14
Siemens SCALANCE X (Update D)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X (Update D)
Last RevisedJuly 14, 2022
Alert CodeICSA-19-085-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.4
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: SCALANCE X
- Vulnerability: Expected Behavior Violation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-19-085-01 Siemens SCALANCE X (Update C) that was published October 14, 2021, to the ICS webpage on us-cert.gov.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to feed data over a mirror port and
Chrome
Stable Channel Update for Desktop: CVE-2020-6569
vendor_chrome·2020-08-25·CVSS 6.3
CVE-2020-6569 [LOW] Stable Channel Update for Desktop: CVE-2020-6569
Stable Channel Update for Desktop
CVE-2020-6569: Integer overflow in WebUSB. Reported by guaixiaomei on 2019-08-20 [$N/A][ 1084699 ] Low CVE-2020-6570: Side-channel information leakage in WebRTC
Reported by Signal/Tenable on 2020-05-19 [$N/A][ 1085315 ] Low CVE-2020-6571: Incorrect security UI in Omnibox
Severity: low
GHSA
GHSA-pq3w-wpr9-q68m: The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network
ghsa_unreviewed·2022-04-30
CVE-2019-6569 [CRITICAL] CWE-440 GHSA-pq3w-wpr9-q68m: The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network
The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-03-26
Published