PT-2019-4791 · Siemens · Scalance Sc-600

Published

2019-08-13

·

Updated

2020-10-02

·

CVE-2019-10928

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SCALANCE SC-600 version V2.0
Description A vulnerability has been identified that allows an authenticated attacker with physical access to the device and access to port 22/tcp to execute arbitrary commands. The vulnerability can be exploited without user interaction and impacts the confidentiality, integrity, and availability of the device. It is related to incorrect handling of exceptional states, which may allow an attacker to execute arbitrary code.
Recommendations For SCALANCE SC-600 version V2.0, consider restricting physical access to the device and limiting access to port 22/tcp to minimize the risk of exploitation. As a temporary workaround, consider disabling access to the device until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01369
CVE-2019-10928

Affected Products

Scalance Sc-600