ZeroHour

CVE-2019-6568

CVSS 3.1
7.5 high
EPSS
1%p71
Published
()
Modified
Description

The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.

Vendors
siemens
Products
cp1604 firmware, cp1616 firmware, simatic rf185c firmware, simatic cp343-1 advanced firmware, simatic cp443-1 firmware, simatic cp443-1 advanced firmware, simatic et 200 sp open controller cpu 1515sp pc firmware, simatic et 200 sp open controller cpu 1515sp pc2 firmware, simatic hmi comfort outdoor panels firmware, simatic hmi comfort panels firmware, simatic hmi ktp mobile panels ktp400f firmware, simatic hmi ktp mobile panels ktp700 firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news