NVD Vulnerability Detail
Search Exploit, PoC
CVE-2019-19301
Summary

A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT, SCALANCE X202-2P IRT PRO, SCALANCE X204-2, SCALANCE X204-2FM, SCALANCE X204-2LD, SCALANCE X204-2LD TS, SCALANCE X204-2TS, SCALANCE X204IRT, SCALANCE X204IRT PRO, SCALANCE X206-1, SCALANCE X206-1LD, SCALANCE X208, SCALANCE X208PRO, SCALANCE X212-2, SCALANCE X212-2LD, SCALANCE X216, SCALANCE X224, SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (2x 230V, coated), SCALANCE X307-2 EEC (2x 230V), SCALANCE X307-2 EEC (2x 24V, coated), SCALANCE X307-2 EEC (2x 24V), SCALANCE X307-3, SCALANCE X307-3, SCALANCE X307-3LD, SCALANCE X307-3LD, SCALANCE X308-2, SCALANCE X308-2, SCALANCE X308-2LD, SCALANCE X308-2LD, SCALANCE X308-2LH, SCALANCE X308-2LH, SCALANCE X308-2LH+, SCALANCE X308-2LH+, SCALANCE X308-2M, SCALANCE X308-2M, SCALANCE X308-2M PoE, SCALANCE X308-2M PoE, SCALANCE X308-2M TS, SCALANCE X308-2M TS, SCALANCE X310, SCALANCE X310, SCALANCE X310FE, SCALANCE X310FE, SCALANCE X320-1 FE, SCALANCE X320-1-2LD FE, SCALANCE X408-2, SCALANCE XF201-3P IRT, SCALANCE XF202-2P IRT, SCALANCE XF204, SCALANCE XF204-2, SCALANCE XF204-2BA IRT, SCALANCE XF204IRT, SCALANCE XF206-1, SCALANCE XF208, SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M TS (24V), SCALANCE XR324-12M TS (24V), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M PoE (230V, ports on front), SCALANCE XR324-4M PoE (230V, ports on rear), SCALANCE XR324-4M PoE (24V, ports on front), SCALANCE XR324-4M PoE (24V, ports on rear), SCALANCE XR324-4M PoE TS (24V, ports on front), SIMATIC CP 343-1 Advanced, SIMATIC CP 442-1 RNA, SIMATIC CP 443-1, SIMATIC CP 443-1, SIMATIC CP 443-1 Advanced, SIMATIC CP 443-1 RNA, SIMATIC RF180C, SIMATIC RF182C, SIPLUS NET CP 343-1 Advanced, SIPLUS NET CP 443-1, SIPLUS NET CP 443-1 Advanced, SIPLUS NET SCALANCE X308-2. The VxWorks-based Profinet TCP Stack can be forced to make very expensive calls for every incoming packet which can lead to a denial of service.

Publication Date April 15, 2020, 5:15 a.m.
Registration Date Jan. 26, 2021, 11:41 a.m.
Last Update Nov. 21, 2024, 1:34 p.m.
CVSS3.1 : HIGH
スコア 7.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR) 不要
利用者の関与(UI) 不要
影響の想定範囲(S) 変更なし
機密性への影響(C) なし
完全性への影響(I) なし
可用性への影響(A)
CVSS2.0 : MEDIUM
Score 5.0
Vector AV:N/AC:L/Au:N/C:N/I:N/A:P
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃前の認証要否(Au) 不要
機密性への影響(C) なし
完全性への影響(I) なし
可用性への影響(A)
Get all privileges. いいえ
Get user privileges いいえ
Get other privileges いいえ
User operation required いいえ
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:siemens:scalance_xf-200_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_xf-200:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:siemens:scalance_x-200irt_firmware:*:*:*:*:*:*:*:* 5.5.0
execution environment
1 cpe:2.3:h:siemens:scalance_x-200irt:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:siemens:scalance_x-200irt_pro_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_x-200irt_pro:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:siemens:scalance_xr-300wg_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_xr-300wg:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:siemens:scalance_x-300_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_x-300:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:siemens:scalance_xr-300_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:scalance_xr-300:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:siemens:simatic_cp_443-1_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:simatic_cp_443-1:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:siemens:simatic_cp_443-1_advanced_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:simatic_cp_443-1_advanced:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:siemens:simatic_rf180c_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:simatic_rf180c:-:*:*:*:*:*:*:*
Configuration13 or higher or less more than less than
cpe:2.3:o:siemens:simatic_rf182c_firmware:*:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:siemens:simatic_rf182c:-:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List

JVN Vulnerability Information
複数のシーメンス製品におけるリソースの枯渇に関する脆弱性
Title 複数のシーメンス製品におけるリソースの枯渇に関する脆弱性
Summary

複数のシーメンス製品には、リソースの枯渇に関する脆弱性が存在します。

Possible impacts サービス運用妨害 (DoS) 状態にされる可能性があります。
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date Nov. 26, 2019, midnight
Registration Date April 20, 2020, 3:54 p.m.
Last Update April 21, 2020, 10:24 a.m.
Affected System
シーメンス
SCALANCE X-200IRT PRO ファームウェア 
SCALANCE X-200IRT ファームウェア 
SCALANCE X-300 ファームウェア 
SCALANCE XB-200 ファームウェア 
SCALANCE XC-200 ファームウェア 
SCALANCE XF-200 ファームウェア 
SCALANCE XP-200 ファームウェア 
SCALANCE XR-300 ファームウェア 
SCALANCE XR-300WG ファームウェア 
SIMATIC CP 443-1 ファームウェア 
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
No Changed Details Date of change
1 [2020年04月20日]
  掲載
April 20, 2020, 3:54 p.m.
2 [2020年04月21日]
  参考情報:ICS-CERT ADVISORY (ICSA-20-105-07) を追加
April 20, 2020, 4:26 p.m.