CVE-2019-6568

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
17/04/2019
Last modified:
11/04/2023

Description

The webserver of the affected devices contains a vulnerability that may lead to<br /> a denial of service condition. An attacker may cause a denial of service<br /> situation which leads to a restart of the webserver of the affected device.<br /> <br /> The security vulnerability could be exploited by an attacker with network<br /> access to the affected systems. Successful exploitation requires no system<br /> privileges and no user interaction. An attacker could use the vulnerability<br /> to compromise availability of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:siemens:cp1604_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp1604:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:cp1616_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp1616:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_rf185c_firmware:*:*:*:*:*:*:*:* 1.1.0 (excluding)
cpe:2.3:h:siemens:simatic_rf185c:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp343-1_advanced_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cp343-1_advanced:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp443-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cp443-1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp443-1_advanced_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cp443-1_advanced:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_et_200_sp_open_controller_cpu_1515sp_pc_firmware:*:*:*:*:*:*:*:* 2.1.6 (excluding)
cpe:2.3:h:siemens:simatic_et_200_sp_open_controller_cpu_1515sp_pc:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_et_200_sp_open_controller_cpu_1515sp_pc2_firmware:*:*:*:*:*:*:*:* 2.7 (excluding)