6.5

CVE-2019-10927

A vulnerability has been identified in SCALANCE SC-600 (V2.0), SCALANCE XB-200 (V4.1), SCALANCE XC-200 (V4.1), SCALANCE XF-200BA (V4.1), SCALANCE XP-200 (V4.1), SCALANCE XR-300WG (V4.1). An authenticated attacker with network access to to port 22/tcp of an affected device may cause a Denial-of-Service condition. The security vulnerability could be exploited by an authenticated attacker with network access to the affected device. No user interaction is required to exploit this vulnerability. The vulnerability impacts the availability of the affected device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Scalance Xb-200 Firmware Version 4.1
   Siemens ≫ Scalance Xb-200 Version -
Siemens ≫ Scalance Xc-200 Firmware Version 4.1
   Siemens ≫ Scalance Xc-200 Version -
Siemens ≫ Scalance Xf-200ba Firmware Version 4.1
   Siemens ≫ Scalance Xf-200ba Version -
Siemens ≫ Scalance Xp-200 Firmware Version 4.1
   Siemens ≫ Scalance Xp-200 Version -
Siemens ≫ Scalance Xr-300wg Firmware Version 4.1
   Siemens ≫ Scalance Xr-300wg Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.17% 0.633
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-703 Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

https://cert-portal.siemens.com/productcert/pdf/ssa-671286.pdf
Patch
Vendor Advisory