CVE-2019-10936

Affected devices improperly handle large amounts of specially crafted UDP packets.

This could allow an unauthenticated remote attacker to trigger a denial of service condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
siemensdk_standard_ethernet_controller_firmware
*
siemensek-ertec_200_firmware
*
siemensek-ertec_200p_firmware
𝑥
< 4.6
siemensek-ertec_200p_firmware
4.6
siemenssimatic_cfu_pa_firmware
𝑥
< 1.2.0
siemenssimatic_et_200al_firmware
*
siemenssimatic_et_200m_firmware
*
siemenssimatic_et_200mp_im_155-5_pn_ba_firmware
𝑥
< 4.3.0
siemenssimatic_et_200mp_im_155-5_pn_hf_firmware
𝑥
< 4.4.0
siemenssimatic_et_200mp_im_155-5_pn_st_firmware
*
siemenssimatic_et_200s_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_ba_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_ha_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_hf_firmware
𝑥
< 4.2.2
siemenssimatic_et_200sp_im_155-6_pn_hs_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_st_firmware
*
siemenssimatic_et_200sp_im_155-6_pn\/2_hf_firmware
𝑥
< 4.2.2
siemenssimatic_et_200sp_im_155-6_pn\/3_hf_firmware
𝑥
< 4.2.1
siemenssimatic_et_200ecopn_firmware
*
siemenssimatic_et_200pro_firmware
*
siemenssimatic_hmi_comfort_outdoor_panels_7\"_firmware
*
siemenssimatic_hmi_comfort_outdoor_panels_15\"_firmware
*
siemenssimatic_hmi_comfort_panels_4\"_firmware
*
siemenssimatic_hmi_comfort_panels_22\"_firmware
*
siemenssimatic_hmi_ktp_mobile_panels_firmware
*
siemenssimatic_pn\/pn_coupler_firmware
𝑥
< 4.2.1
siemenssimatic_profinet_driver_firmware
𝑥
< 2.1
siemenssimatic_s7-1200_cpu_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1200_cpu_1211c_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1200_cpu_1212c_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1200_cpu_1214c_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1500_cpu_firmware
𝑥
< 2.0
siemenssimatic_s7-1500s_cpu_firmware
𝑥
< 2.0
siemenssimatic_s7-1500t_cpu_firmware
𝑥
< 2.0
siemenssimatic_s7-1500_cpu_1518_firmware
𝑥
< 2.0
siemenssimatic_s7-1500_cpu_1511c_firmware
𝑥
< 2.0
siemenssimatic_s7-1500_cpu_1512c_firmware
𝑥
< 2.0
siemenssimatic_s7-300_cpu_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_312_ifm_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_313_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_314_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_314_ifm_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_315_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_315-2_dp_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_316-2_dp_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_318-2_firmware
𝑥
< 3.3.17
siemenssimatic_s7-400_pn_v7_firmware
*
siemenssimatic_s7-400_dp_v7_firmware
*
siemenssimatic_s7-400_v6_firmware
𝑥
< 6.0.9
siemenssimatic_s7-400h_v6_firmware
𝑥
< 6.0.9
siemenssimatic_s7-410_v8_firmware
𝑥
< 8.2.2
siemenssimatic_winac_rtx_\(f\)_firmware
𝑥
< 2010
siemenssinamics_dcm_firmware
𝑥
< 1.5
siemenssinamics_dcm_firmware
1.5
siemenssinamics_dcp_firmware
𝑥
< 1.3
siemenssinamics_g110m_firmware
𝑥
< 4.7
siemenssinamics_g110m_firmware
4.7
siemenssinamics_g120_firmware
𝑥
< 4.7
siemenssinamics_g120_firmware
4.7
siemenssinamics_g130_firmware
𝑥
< 5.2
siemenssinamics_g130_firmware
5.2
siemenssinamics_g150_firmware
𝑥
< 5.2
siemenssinamics_g150_firmware
5.2
siemenssinamics_gl150_firmware
𝑥
< 4.8
siemenssinamics_gl150_firmware
4.8
siemenssinamics_gm150_firmware
𝑥
< 4.8
siemenssinamics_gm150_firmware
4.8
siemenssinamics_s110_firmware
*
siemenssinamics_s120_firmware
𝑥
< 5.2
siemenssinamics_s120_firmware
5.2
siemenssinamics_s150_firmware
𝑥
< 5.2
siemenssinamics_s150_firmware
5.2
siemenssinamics_sl150_firmware
𝑥
< 4.7
siemenssinamics_sl150_firmware
4.7
siemenssinamics_sm120_firmware
-
siemenssinumerik_828d
𝑥
< 4.8
siemenssinumerik_828d
4.8
siemenssinumerik_828d
4.8:sp1
siemenssinumerik_828d
4.8:sp2
siemenssinumerik_828d
4.8:sp3
siemenssinumerik_828d
4.8:sp4
siemenssinumerik_840d_sl
*
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
siemensdk_standard_ethernet_controller_firmware
𝑥
≤ *
ADP
siemensek-ertec_200_firmware
𝑥
< *
ADP
siemensek-ertec_200p_firmware
𝑥
< 4.6
ADP
siemenssimatic_cfu_pa
𝑥
< v1.2.0
ADP
siemenssimatic_et200ecopn_firmware
𝑥
≤ *
ADP
siemenssimatic_et200s_firmware
𝑥
≤ *
ADP
siemenssimatic_et_200al_firmware
𝑥
≤ *
ADP
siemenssimatic_et_200m_firmware
𝑥
≤ *
ADP
siemenssimatic_et_200mp_firmware
𝑥
< v4.3.0
ADP
siemenssimatic_et_200pro_firmware
𝑥
≤ *
ADP
siemenssimatic_et_200s_firmware
𝑥
< v3.2.17
ADP
siemenssimatic_et_200sp_firmware
𝑥
≤ *
ADP
siemenssimatic_hmi_comfort_outdoor_panels
𝑥
≤ *
ADP
siemenssimatic_pn\/pn_coupler_6es7158-3ad01-0xa0
𝑥
< v4.2.1
ADP
siemenssimatic_profinet_driver
𝑥
< v2.1
ADP
siemenssimatic_s7-300_cpu_314_firmware
𝑥
< v3.2.17
ADP
siemenssimatic_s7-300_cpu_315-2_dp_firmware
𝑥
< v3.2.17
ADP
siemenssimatic_s7-300_cpu_315f-2_dp_firmware
𝑥
< v3.2.17
ADP
siemenssimatic_s7-300_cpu_317-2_dp_firmware
𝑥
< v3.2.17
ADP
siemenssimatic_s7-300_cpu_317-2_pn\/dp_firmware
𝑥
< v3.2.17
ADP
siemenssimatic_s7-300_cpu_319-3_pn\/dp_firmware
𝑥
< v3.2.17
ADP
siemenssimatic_s7-400_cpu_412-2_pn
𝑥
< v7.0.3
ADP
siemenssimatic_s7-400_cpu_414-3_pn\/dp
𝑥
< v7.0.3
ADP
siemenssimatic_s7-400_cpu_416-3_pn\/dp
𝑥
≤ v7.0.3
ADP
siemenssimatic_s7-400_h_v6_firmware
𝑥
≤ v6.0.9
ADP
siemenssimatic_s7-400_pn\/dp_v6_firmware
𝑥
≤ *
ADP
siemenssimatic_s7-410_cpu_firmware
𝑥
< v8.2.2
ADP
siemenssimatic_s7-1200_cpu
𝑥
< v4.4.0
ADP
siemenssimatic_s7-1500_cpu
𝑥
< v2.0
ADP
siemenssimatic_s7-1500_controller
𝑥
< v2.0
ADP
siemenssimatic_tdc_cp51m1_firmware
𝑥
< v1.1.8
ADP
siemenssimatic_tdc_cpu555_firmware
𝑥
< v1.1.1
ADP
siemenssimatic_winac_rtx_2010
𝑥
< v2010_sp3
ADP
siemenssimatic_winac_rtx_\(f\)_2010
𝑥
< v2010_sp3
ADP
siemenssinamics_dcm
𝑥
< v1.5_hf1
ADP
siemenssinamics_dcp
𝑥
< v1.3
ADP
siemenssinamics_g110m
𝑥
< v4.7_sp10_hf5
ADP
siemenssinamics_g120
𝑥
< v4.7_sp10_hf5
ADP
siemenssinamics_g130
𝑥
< v4.8
ADP
siemenssinamics_g150
𝑥
< v4.8
ADP
siemenssinamics_gh150
𝑥
≤ *
ADP
siemenssinamics_gl150
𝑥
≤ *
ADP
siemenssinamics_gm150
𝑥
< *
ADP
siemenssinamics_s110
𝑥
≤ *
ADP
siemenssinamics_s120
𝑥
≤ *
ADP
siemenssinamics_sl150
𝑥
< v4.8
ADP
siemenssinamics_sl150
𝑥
< v4.7_hf33
ADP
siemenssinamics_sm120
𝑥
≤ *
ADP
siemenssinumerik_828d
𝑥
< v4.8_sp5
ADP
siemenssinumerik_840d_sl
𝑥
< v4.8_sp6
ADP
siemenssiplus_s7-300_cpu_314
𝑥
< v3.3.17
ADP