7.8

CVE-2019-13946

Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit
internal resource allocation when multiple legitimate diagnostic package
requests are sent to the DCE-RPC interface.
This could lead to a denial of service condition due to lack of memory
for devices that include a vulnerable version of the stack.

The security vulnerability could be exploited by an attacker with network
access to an affected device. Successful exploitation requires no system
privileges and no user interaction. An attacker could use the vulnerability
to compromise the availability of the device.

Data is provided by the National Vulnerability Database (NVD)
SiemensProfinet Driver Version < 2.1
SiemensEk-ertec 200 Firmware Version < 4.5
   SiemensEk-ertec 200 Version-
SiemensEk-ertec 200p Firmware Version < 4.6
   SiemensEk-ertec 200p Version-
SiemensRuggedcom Rm1224 Firmware Version < 4.3
   SiemensRuggedcom Rm1224 Version-
SiemensScalance M-800 Firmware Version < 4.3
   SiemensScalance M-800 Version-
SiemensScalance S615 Firmware Version < 4.3
   SiemensScalance S615 Version-
SiemensScalance X-200irt Firmware Version < 5.3
   SiemensScalance X-200irt Version-
SiemensScalance Xr-300wg Firmware Version < 3.0
   SiemensScalance Xr-300wg Version-
SiemensScalance Xb-200 Firmware Version < 3.0
   SiemensScalance Xb-200 Version-
SiemensScalance Xc-200 Firmware Version < 3.0
   SiemensScalance Xc-200 Version-
SiemensScalance Xp-200 Firmware Version < 3.0
   SiemensScalance Xp-200 Version-
SiemensScalance Xf-200ba Firmware Version < 3.0
   SiemensScalance Xf-200ba Version-
SiemensScalance Xr-300wg Firmware Version < 3.0
   SiemensScalance Xr-300wg Version-
SiemensScalance X-400 Firmware Version < 6.0
   SiemensScalance X-400 Version-
SiemensScalance Xm-400 Firmware Version < 6.0
   SiemensScalance Xm-400 Version-
SiemensScalance Xr524 Firmware Version < 6.0
   SiemensScalance Xr524 Version-
SiemensScalance Xr526 Firmware Version < 6.0
   SiemensScalance Xr526 Version-
SiemensScalance Xr528 Firmware Version < 6.0
   SiemensScalance Xr528 Version-
SiemensScalance Xr552 Firmware Version < 6.0
   SiemensScalance Xr552 Version-
SiemensSimatic Cp 1616 Firmware Version < 2.8
   SiemensSimatic Cp 1616 Version-
SiemensSimatic Cp 1604 Firmware Version < 2.8
   SiemensSimatic Cp 1604 Version-
SiemensSimatic Rf600 Firmware Version < 3.0
   SiemensSimatic Rf600 Version-
SiemensSinamics Dcp Firmware Version < 1.3
   SiemensSinamics Dcp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.55% 0.67
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
productcert@siemens.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.