PT-2019-2286 · Siemens · Logo! 8 Bm

Manuel Stotz

+1

·

Publicado

2019-05-14

·

Atualizado

2022-01-04

·

CVE-2019-10919

CVSS v2.0

9.7

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions LOGO! 8 BM (incl. SIPLUS variants) versions prior to V8.3
Description A security issue has been identified that allows attackers with access to port 10005/tcp to reconfigure devices and obtain project files. This can be exploited by an unauthenticated attacker with network access to the mentioned port, without requiring any user interaction. The issue affects the confidentiality, integrity, and availability of the device. At the time of reporting, there were no known public exploitations of this issue. The exploitation is related to errors in access control.
Recommendations For versions prior to V8.3, as a temporary workaround, consider restricting access to port 10005/tcp to minimize the risk of exploitation. Additionally, follow the system manual's recommendation to protect access to this port. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02057
CVE-2019-10919

Produtos afetados

Logo! 8 Bm