7.5

CVE-2019-10931

A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions ), DIGSI 5 engineering software (All versions < V7.90), SIPROTEC 5 device types 6MD85, 6MD86, 6MD89, 7UM85, 7SA87, 7SD87, 7SL87, 7VK87, 7SA82, 7SA86, 7SD82, 7SD86, 7SL82, 7SL86, 7SJ86, 7SK82, 7SK85, 7SJ82, 7SJ85, 7UT82, 7UT85, 7UT86, 7UT87 and 7VE85 with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.90), SIPROTEC 5 device types 7SS85 and 7KE85 (All versions < V8.01), SIPROTEC 5 device types with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.59), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.59). Specially crafted packets sent to port 443/TCP could cause a Denial of Service condition.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensSiprotec 5 Digsi Device Driver Version < 7.90
   Siemens6md85 Version-
   Siemens6md86 Version-
   Siemens6md89 Version-
   Siemens7sa82 Version-
   Siemens7sa86 Version-
   Siemens7sa87 Version-
   Siemens7sd82 Version-
   Siemens7sd86 Version-
   Siemens7sd87 Version-
   Siemens7sj82 Version-
   Siemens7sj85 Version-
   Siemens7sj86 Version-
   Siemens7sk82 Version-
   Siemens7sk85 Version-
   Siemens7sl82 Version-
   Siemens7sl86 Version-
   Siemens7sl87 Version-
   Siemens7um85 Version-
   Siemens7ut82 Version-
   Siemens7ut85 Version-
   Siemens7ut86 Version-
   Siemens7ut87 Version-
   Siemens7ve85 Version-
   Siemens7vk87 Version-
SiemensSiprotec 5 Digsi Device Driver Version < 8.01
   Siemens7ke85 Version-
   Siemens7ss85 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.375
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-248 Uncaught Exception

An exception is thrown from a function, but it is not caught.