HIGH · 7.5

CVE-2019-10936

Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

Vulnerability Description

Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
SiemensDk Standard Ethernet Controller FirmwareAll versions
SiemensDk Standard Ethernet Controller-
SiemensEk-Ertec 200 FirmwareAll versions
SiemensEk-Ertec 200-
SiemensEk-Ertec 200P Firmware< 4.6
SiemensEk-Ertec 200P-
SiemensSimatic Cfu Pa Firmware< 1.2.0
SiemensSimatic Cfu Pa-
SiemensSimatic Et 200Al FirmwareAll versions
SiemensSimatic Et 200Al-
SiemensSimatic Et 200M FirmwareAll versions
SiemensSimatic Et 200M-
SiemensSimatic Et 200Mp Im 155-5 Pn Ba Firmware< 4.3.0
SiemensSimatic Et 200Mp Im 155-5 Pn Ba-
SiemensSimatic Et 200Mp Im 155-5 Pn Hf Firmware< 4.4.0
SiemensSimatic Et 200Mp Im 155-5 Pn Hf-
SiemensSimatic Et 200Mp Im 155-5 Pn St FirmwareAll versions
SiemensSimatic Et 200Mp Im 155-5 Pn St-
SiemensSimatic Et 200S FirmwareAll versions
SiemensSimatic Et 200S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-10936?

CVE-2019-10936 is a vulnerability with a CVSS score of 7.5 (HIGH). Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

How severe is CVE-2019-10936?

CVE-2019-10936 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-10936?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Dk Standard Ethernet Controller Firmware, Siemens Dk Standard Ethernet Controller, Siemens Ek-Ertec 200 Firmware, Siemens Ek-Ertec 200, Siemens Ek-Ertec 200P Firmware.