CVE-2019-10937
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to the device could cause a Denial-of-Service condition by sending a specially crafted UDP packet. The vulnerability affects the UDP communication of the device. The security vulnerability could be exploited without authentication. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.
Se ha identificado una vulnerabilidad en SIMATIC TDC CP51M1 (Todas las versiones anteriores a V1.1.7). Un atacante con acceso de red al dispositivo podría causar una condición de Denegación de Servicio mediante el envío de un paquete UDP especialmente diseñado. La vulnerabilidad afecta la comunicación UDP del dispositivo. La vulnerabilidad de seguridad podría ser explotada sin autenticación. No es requerida la interacción del usuario para explotar esta vulnerabilidad de seguridad. Una explotación con éxito de la vulnerabilidad de seguridad compromete la disponibilidad del sistema apuntado. Al momento de la publicación de asesoramiento, no se conocía una explotación pública de esta vulnerabilidad de seguridad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-08 CVE Reserved
- 2019-09-13 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsa-19-253-05 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-250618.pdf | 2019-09-24 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Tdc Cp51m1 Firmware Search vendor "Siemens" for product "Simatic Tdc Cp51m1 Firmware" | < 1.1.7 Search vendor "Siemens" for product "Simatic Tdc Cp51m1 Firmware" and version " < 1.1.7" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Tdc Cp51m1 Search vendor "Siemens" for product "Simatic Tdc Cp51m1" | - | - |
Safe
|