CVE-2019-13946
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/02/2020
Last modified:
09/07/2024
Description
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit<br />
internal resource allocation when multiple legitimate diagnostic package<br />
requests are sent to the DCE-RPC interface.<br />
This could lead to a denial of service condition due to lack of memory<br />
for devices that include a vulnerable version of the stack.<br />
<br />
The security vulnerability could be exploited by an attacker with network<br />
access to an affected device. Successful exploitation requires no system<br />
privileges and no user interaction. An attacker could use the vulnerability<br />
to compromise the availability of the device.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:siemens:dk_standard_ethernet_controller:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:siemens:profinet_driver:*:*:*:*:*:*:*:* | 2.1 (excluding) | |
| cpe:2.3:a:siemens:simatic_ipc_support:*:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ek-ertec_200_firmware:*:*:*:*:*:*:*:* | 4.5 (excluding) | |
| cpe:2.3:h:siemens:ek-ertec_200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ek-ertec_200p_firmware:*:*:*:*:*:*:*:* | 4.6 (excluding) | |
| cpe:2.3:h:siemens:ek-ertec_200p:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:ruggedcom_rm1224_firmware:*:*:*:*:*:*:*:* | 4.3 (excluding) | |
| cpe:2.3:h:siemens:ruggedcom_rm1224:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:scalance_m-800_firmware:*:*:*:*:*:*:*:* | 4.3 (excluding) | |
| cpe:2.3:h:siemens:scalance_m-800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:scalance_s615_firmware:*:*:*:*:*:*:*:* | 4.3 (excluding) | |
| cpe:2.3:h:siemens:scalance_s615:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:scalance_w700_ieee_802.11n_firmware:*:*:*:*:*:*:*:* | 6.0.1 (including) | |
| cpe:2.3:h:siemens:scalance_w700_ieee_802.11n:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



