ZeroHour

CVE-2019-10926

CVSS 3.0
5.3 medium
EPSS
2%p74
Published
()
Modified
Description

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.

Vendors
siemens
Products
simatic mv420 firmware, simatic mv440 firmware
Weakness
CWE-319, CWE-310
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.