PT-2019-2286 · Siemens · Logo! 8 Bm

Manuel Stotz

+1

·

Published

2019-05-14

·

Updated

2022-01-04

·

CVE-2019-10919

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions LOGO! 8 BM (incl. SIPLUS variants) versions prior to V8.3
Description A security issue has been identified that allows attackers with access to port 10005/tcp to reconfigure devices and obtain project files. This can be exploited by an unauthenticated attacker with network access to the mentioned port, without requiring any user interaction. The issue affects the confidentiality, integrity, and availability of the device. At the time of reporting, there were no known public exploitations of this issue. The exploitation is related to errors in access control.
Recommendations For versions prior to V8.3, as a temporary workaround, consider restricting access to port 10005/tcp to minimize the risk of exploitation. Additionally, follow the system manual's recommendation to protect access to this port. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02057
CVE-2019-10919

Affected Products

Logo! 8 Bm