Vulnerability Description
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Cp1604 Firmware | All versions |
| Siemens | Cp1604 | - |
| Siemens | Cp1616 Firmware | All versions |
| Siemens | Cp1616 | - |
| Siemens | Simatic Rf185C Firmware | < 1.1.0 |
| Siemens | Simatic Rf185C | - |
| Siemens | Simatic Cp343-1 Advanced Firmware | All versions |
| Siemens | Simatic Cp343-1 Advanced | - |
| Siemens | Simatic Cp443-1 Firmware | All versions |
| Siemens | Simatic Cp443-1 | - |
| Siemens | Simatic Cp443-1 Advanced Firmware | All versions |
| Siemens | Simatic Cp443-1 Advanced | - |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515Sp Pc Firmware | < 2.1.6 |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515Sp Pc | - |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515Sp Pc2 Firmware | < 2.7 |
| Siemens | Simatic Et 200 Sp Open Controller Cpu 1515Sp Pc2 | - |
| Siemens | Simatic Hmi Comfort Outdoor Panels Firmware | < 15.1 |
| Siemens | Simatic Hmi Comfort Outdoor Panels | - |
| Siemens | Simatic Hmi Comfort Panels Firmware | < 15.1 |
| Siemens | Simatic Hmi Comfort Panels | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-480230.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-480230.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdfVendor Advisory
FAQ
What is CVE-2019-6568?
CVE-2019-6568 is a vulnerability with a CVSS score of 7.5 (HIGH). The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the web...
How severe is CVE-2019-6568?
CVE-2019-6568 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6568?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Cp1604 Firmware, Siemens Cp1604, Siemens Cp1616 Firmware, Siemens Cp1616, Siemens Simatic Rf185C Firmware.