PT-2020-2003 · Siemens · Sinamics Perfect Harmony Gh180 Drives

Published

2020-01-14

·

Updated

2021-11-03

·

CVE-2019-19278

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-.... (All versions) SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR4...-.....-.... (All versions) SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR5...-.....-.... (All versions) SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR325.-.....-.... (All versions)
Description The issue is related to insufficient input validation, which could allow an attacker to compromise the confidentiality, integrity, and availability of the device. Successful exploitation requires physical access to the system but does not require system privileges or user interaction. The vulnerability could be used to restore the device to a state where predefined application and operating system protection mechanisms are not in place.
Recommendations For SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-...., restrict physical access to the system to minimize the risk of exploitation. For SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR4...-.....-...., restrict physical access to the system to minimize the risk of exploitation. For SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR5...-.....-...., restrict physical access to the system to minimize the risk of exploitation. For SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR325.-.....-...., restrict physical access to the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Race Condition

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01388
CVE-2019-19278

Affected Products

Sinamics Perfect Harmony Gh180 Drives