CVE-2019-13946
| Summary |
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack.
The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.
|
| Publication Date |
Feb. 12, 2020, 1:15 a.m. |
| Registration Date |
Jan. 26, 2021, 11:38 a.m. |
| Last Update |
Nov. 21, 2024, 1:25 p.m. |
|
CVSS3.1 : HIGH
|
| スコア |
7.5
|
| Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 攻撃元区分(AV) |
ネットワーク |
| 攻撃条件の複雑さ(AC) |
低 |
| 攻撃に必要な特権レベル(PR) |
不要 |
| 利用者の関与(UI) |
不要 |
| 影響の想定範囲(S) |
変更なし |
| 機密性への影響(C) |
なし |
| 完全性への影響(I) |
なし |
| 可用性への影響(A) |
高 |
|
CVSS2.0 : HIGH
|
| Score |
7.8
|
| Vector |
AV:N/AC:L/Au:N/C:N/I:N/A:C |
| 攻撃元区分(AV) |
ネットワーク |
| 攻撃条件の複雑さ(AC) |
低 |
| 攻撃前の認証要否(Au) |
不要 |
| 機密性への影響(C) |
なし |
| 完全性への影響(I) |
なし |
| 可用性への影響(A) |
高 |
| Get all privileges. |
いいえ
|
| Get user privileges |
いいえ
|
| Get other privileges |
いいえ
|
| User operation required |
いいえ
|
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:siemens:profinet_driver:*:*:*:*:*:*:*:* |
|
|
|
2.1 |
| cpe:2.3:a:siemens:dk_standard_ethernet_controller:*:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:siemens:simatic_ipc_support:*:*:*:*:*:*:*:* |
|
|
|
|
| Configuration2 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:ek-ertec_200_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.5 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:ek-ertec_200:-:*:*:*:*:*:*:* |
| Configuration3 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:ek-ertec_200p_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.6 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:ek-ertec_200p:-:*:*:*:*:*:*:* |
| Configuration4 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:ruggedcom_rm1224_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.3 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:ruggedcom_rm1224:-:*:*:*:*:*:*:* |
| Configuration5 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_m-800_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.3 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_m-800:-:*:*:*:*:*:*:* |
| Configuration6 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_s615_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.3 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_s615:-:*:*:*:*:*:*:* |
| Configuration7 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_w700_ieee_802.11n_firmware:*:*:*:*:*:*:*:* |
|
6.0.1 |
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_w700_ieee_802.11n:-:*:*:*:*:*:*:* |
| Configuration8 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:* |
| Configuration9 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xf-200_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xf-200:-:*:*:*:*:*:*:* |
| Configuration10 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:* |
| Configuration11 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:* |
| Configuration12 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_x-200irt_firmware:*:*:*:*:*:*:*:* |
|
|
|
5.3 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_x-200irt:-:*:*:*:*:*:*:* |
| Configuration13 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xr-300wg_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xr-300wg:-:*:*:*:*:*:*:* |
| Configuration14 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_x-300_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_x-300:-:*:*:*:*:*:*:* |
| Configuration15 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:* |
| Configuration16 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:* |
| Configuration17 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:* |
| Configuration18 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xf-200ba_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xf-200ba:-:*:*:*:*:*:*:* |
| Configuration19 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xr-300wg_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xr-300wg:-:*:*:*:*:*:*:* |
| Configuration20 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_x-400_firmware:*:*:*:*:*:*:*:* |
|
|
|
6.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_x-400:-:*:*:*:*:*:*:* |
| Configuration21 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xm-400_firmware:*:*:*:*:*:*:*:* |
|
|
|
6.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xm-400:-:*:*:*:*:*:*:* |
| Configuration22 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xr524_firmware:*:*:*:*:*:*:*:* |
|
|
|
6.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xr524:-:*:*:*:*:*:*:* |
| Configuration23 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xr526_firmware:*:*:*:*:*:*:*:* |
|
|
|
6.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xr526:-:*:*:*:*:*:*:* |
| Configuration24 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xr528_firmware:*:*:*:*:*:*:*:* |
|
|
|
6.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xr528:-:*:*:*:*:*:*:* |
| Configuration25 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:scalance_xr552_firmware:*:*:*:*:*:*:*:* |
|
|
|
6.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:scalance_xr552:-:*:*:*:*:*:*:* |
| Configuration26 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_1616_firmware:*:*:*:*:*:*:*:* |
|
|
|
2.8 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_1616:-:*:*:*:*:*:*:* |
| Configuration27 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_1604_firmware:*:*:*:*:*:*:*:* |
|
|
|
2.8 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_1604:-:*:*:*:*:*:*:* |
| Configuration28 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_343-1_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_343-1:-:*:*:*:*:*:*:* |
| Configuration29 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_343-1_advanced_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_343-1_advanced:-:*:*:*:*:*:*:* |
| Configuration30 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_343-1_erpc_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_343-1_erpc:-:*:*:*:*:*:*:* |
| Configuration31 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_343-1_lean_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_343-1_lean:-:*:*:*:*:*:*:* |
| Configuration32 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_443-1_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_443-1:-:*:*:*:*:*:*:* |
| Configuration33 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_443-1_advanced_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_443-1_advanced:-:*:*:*:*:*:*:* |
| Configuration34 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_cp_443-1_opc_ua_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_cp_443-1_opc_ua:-:*:*:*:*:*:*:* |
| Configuration35 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200al_im_157-1_pn_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200al_im_157-1_pn:-:*:*:*:*:*:*:* |
| Configuration36 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200m_im153-4_pn_io_hf_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200m_im153-4_pn_io_hf:-:*:*:*:*:*:*:* |
| Configuration37 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200m_im153-4_pn_io_st_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200m_im153-4_pn_io_st:-:*:*:*:*:*:*:* |
| Configuration38 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200mp_im155-5_pn_hf_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.2.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200mp_im155-5_pn_hf:-:*:*:*:*:*:*:* |
| Configuration39 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200mp_im155-5_pn_st_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.1.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200mp_im155-5_pn_st:-:*:*:*:*:*:*:* |
| Configuration40 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200s_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200s:-:*:*:*:*:*:*:* |
| Configuration41 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200sp_im155-6_pn_basic_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200sp_im155-6_pn_basic:-:*:*:*:*:*:*:* |
| Configuration42 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200sp_im155-6_pn_hf_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.3.1 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200sp_im155-6_pn_hf:-:*:*:*:*:*:*:* |
| Configuration43 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200sp_im155-6_pn_st_firmware:*:*:*:*:*:*:*:* |
|
|
|
4.1.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200sp_im155-6_pn_st:-:*:*:*:*:*:*:* |
| Configuration44 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200ecopn_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200ecopn:-:*:*:*:*:*:*:* |
| Configuration45 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_et200pro_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_et200pro:-:*:*:*:*:*:*:* |
| Configuration46 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:im_154-3_pn_hf_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:im_154-3_pn_hf:-:*:*:*:*:*:*:* |
| Configuration47 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:im_154-4_pn_hf_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:im_154-4_pn_hf:-:*:*:*:*:*:*:* |
| Configuration48 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_mv440_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_mv440:-:*:*:*:*:*:*:* |
| Configuration49 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_mv420_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_mv420:-:*:*:*:*:*:*:* |
| Configuration50 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_pn\/pn_coupler_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_pn\/pn_coupler:-:*:*:*:*:*:*:* |
| Configuration51 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_rf180c_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_rf180c:-:*:*:*:*:*:*:* |
| Configuration52 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_rf182c_firmware:*:*:*:*:*:*:*:* |
|
|
|
|
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_rf182c:-:*:*:*:*:*:*:* |
| Configuration53 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:simatic_rf600_firmware:*:*:*:*:*:*:*:* |
|
|
|
3.0 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:simatic_rf600:-:*:*:*:*:*:*:* |
| Configuration54 |
or higher |
or less |
more than |
less than |
| cpe:2.3:o:siemens:sinamics_dcp_firmware:*:*:*:*:*:*:*:* |
|
|
|
1.3 |
| execution environment |
| 1 |
cpe:2.3:h:siemens:sinamics_dcp:-:*:*:*:*:*:*:* |
Related information, measures and tools
Common Vulnerabilities List
JVN Vulnerability Information
複数のシーメンス製品におけるリソースの枯渇に関する脆弱性
| Title |
複数のシーメンス製品におけるリソースの枯渇に関する脆弱性
|
| Summary |
複数のシーメンス製品には、リソースの枯渇に関する脆弱性が存在します。
|
| Possible impacts |
サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
July 18, 2019, midnight |
| Registration Date |
March 4, 2020, 9:18 a.m. |
| Last Update |
March 11, 2020, 5:28 p.m. |
Affected System
| シーメンス |
|
DK Standard Ethernet Controller ファームウェア
|
|
EK-ERTEC 200 ファームウェア
|
|
EK-ERTEC 200P P ファームウェア
|
|
PROFINET Driver
|
|
RUGGEDCOM RM1224 ファームウェア
|
|
SCALANCE M-800 ファームウェア
|
|
SCALANCE S615 ファームウェア
|
|
SCALANCE W700 IEEE 802.11n ファームウェア
|
|
SCALANCE XC-200 ファームウェア
|
|
SIMATIC IPC Support
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2020年03月04日] 掲載 |
March 4, 2020, 9:18 a.m. |
| 2 |
[2020年03月11日] 参考情報:ICS-CERT ADVISORY (ICSA-20-042-04) を追加 |
March 11, 2020, 3:52 p.m. |