HIGH · 7.5

CVE-2019-13946

Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lea...

Vulnerability Description

Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
SiemensDk Standard Ethernet ControllerAll versions
SiemensProfinet Driver< 2.1
SiemensSimatic Ipc SupportAll versions
SiemensEk-Ertec 200 Firmware< 4.5
SiemensEk-Ertec 200-
SiemensEk-Ertec 200P Firmware< 4.6
SiemensEk-Ertec 200P-
SiemensRuggedcom Rm1224 Firmware< 4.3
SiemensRuggedcom Rm1224-
SiemensScalance M-800 Firmware< 4.3
SiemensScalance M-800-
SiemensScalance S615 Firmware< 4.3
SiemensScalance S615-
SiemensScalance W700 Ieee 802.11N Firmware<= 6.0.1
SiemensScalance W700 Ieee 802.11N-
SiemensScalance Xc-200 FirmwareAll versions
SiemensScalance Xc-200-
SiemensScalance Xf-200 FirmwareAll versions
SiemensScalance Xf-200-
SiemensScalance Xp-200 FirmwareAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-13946?

CVE-2019-13946 is a vulnerability with a CVSS score of 7.5 (HIGH). Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lea...

How severe is CVE-2019-13946?

CVE-2019-13946 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-13946?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Dk Standard Ethernet Controller, Siemens Profinet Driver, Siemens Simatic Ipc Support, Siemens Ek-Ertec 200 Firmware, Siemens Ek-Ertec 200.