CVE-2019-10936

Affected devices improperly handle large amounts of specially crafted UDP packets.

This could allow an unauthenticated remote attacker to trigger a denial of service condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
siemensCNA
7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
siemensdk_standard_ethernet_controller_firmware
*
siemensek-ertec_200_firmware
*
siemensek-ertec_200p_firmware
𝑥
< 4.6
siemensek-ertec_200p_firmware
4.6
siemenssimatic_cfu_pa_firmware
𝑥
< 1.2.0
siemenssimatic_et_200al_firmware
*
siemenssimatic_et_200m_firmware
*
siemenssimatic_et_200mp_im_155-5_pn_ba_firmware
𝑥
< 4.3.0
siemenssimatic_et_200mp_im_155-5_pn_hf_firmware
𝑥
< 4.4.0
siemenssimatic_et_200mp_im_155-5_pn_st_firmware
*
siemenssimatic_et_200s_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_ba_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_ha_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_hf_firmware
𝑥
< 4.2.2
siemenssimatic_et_200sp_im_155-6_pn_hs_firmware
*
siemenssimatic_et_200sp_im_155-6_pn_st_firmware
*
siemenssimatic_et_200sp_im_155-6_pn\/2_hf_firmware
𝑥
< 4.2.2
siemenssimatic_et_200sp_im_155-6_pn\/3_hf_firmware
𝑥
< 4.2.1
siemenssimatic_et_200ecopn_firmware
*
siemenssimatic_et_200pro_firmware
*
siemenssimatic_hmi_comfort_outdoor_panels_7\"_firmware
*
siemenssimatic_hmi_comfort_outdoor_panels_15\"_firmware
*
siemenssimatic_hmi_comfort_panels_4\"_firmware
*
siemenssimatic_hmi_comfort_panels_22\"_firmware
*
siemenssimatic_hmi_ktp_mobile_panels_firmware
*
siemenssimatic_pn\/pn_coupler_firmware
𝑥
< 4.2.1
siemenssimatic_profinet_driver_firmware
𝑥
< 2.1
siemenssimatic_s7-1200_cpu_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1200_cpu_1211c_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1200_cpu_1212c_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1200_cpu_1214c_firmware
𝑥
< 4.4.0
siemenssimatic_s7-1500_cpu_firmware
𝑥
< 2.0
siemenssimatic_s7-1500s_cpu_firmware
𝑥
< 2.0
siemenssimatic_s7-1500t_cpu_firmware
𝑥
< 2.0
siemenssimatic_s7-1500_cpu_1518_firmware
𝑥
< 2.0
siemenssimatic_s7-1500_cpu_1511c_firmware
𝑥
< 2.0
siemenssimatic_s7-1500_cpu_1512c_firmware
𝑥
< 2.0
siemenssimatic_s7-300_cpu_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_312_ifm_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_313_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_314_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_314_ifm_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_315_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_315-2_dp_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_316-2_dp_firmware
𝑥
< 3.3.17
siemenssimatic_s7-300_cpu_318-2_firmware
𝑥
< 3.3.17
siemenssimatic_s7-400_pn_v7_firmware
*
siemenssimatic_s7-400_dp_v7_firmware
*
siemenssimatic_s7-400_v6_firmware
𝑥
< 6.0.9
siemenssimatic_s7-400h_v6_firmware
𝑥
< 6.0.9
siemenssimatic_s7-410_v8_firmware
𝑥
< 8.2.2
siemenssimatic_winac_rtx_\(f\)_firmware
𝑥
< 2010
siemenssinamics_dcm_firmware
𝑥
< 1.5
siemenssinamics_dcm_firmware
1.5
siemenssinamics_dcp_firmware
𝑥
< 1.3
siemenssinamics_g110m_firmware
𝑥
< 4.7
siemenssinamics_g110m_firmware
4.7
siemenssinamics_g120_firmware
𝑥
< 4.7
siemenssinamics_g120_firmware
4.7
siemenssinamics_g130_firmware
𝑥
< 5.2
siemenssinamics_g130_firmware
5.2
siemenssinamics_g150_firmware
𝑥
< 5.2
siemenssinamics_g150_firmware
5.2
siemenssinamics_gl150_firmware
𝑥
< 4.8
siemenssinamics_gl150_firmware
4.8
siemenssinamics_gm150_firmware
𝑥
< 4.8
siemenssinamics_gm150_firmware
4.8
siemenssinamics_s110_firmware
*
siemenssinamics_s120_firmware
𝑥
< 5.2
siemenssinamics_s120_firmware
5.2
siemenssinamics_s150_firmware
𝑥
< 5.2
siemenssinamics_s150_firmware
5.2
siemenssinamics_sl150_firmware
𝑥
< 4.7
siemenssinamics_sl150_firmware
4.7
siemenssinamics_sm120_firmware
-
siemenssinumerik_828d
𝑥
< 4.8
siemenssinumerik_828d
4.8
siemenssinumerik_828d
4.8:sp1
siemenssinumerik_828d
4.8:sp2
siemenssinumerik_828d
4.8:sp3
siemenssinumerik_828d
4.8:sp4
siemenssinumerik_840d_sl
*
𝑥
= Vulnerable software versions