PT-2020-2433 · Siemens · Profinet-Io

Published

2020-02-11

·

Updated

2024-07-09

·

CVE-2019-13946

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Profinet-IO (PNIO) stack versions prior to V06.00
Description The issue is related to an uncontrolled resource consumption in the DCE-RPC interface of Siemens hardware and software. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. An attacker with network access to an affected device can exploit this issue without requiring system privileges or user interaction, compromising the availability of the device.
Recommendations For Profinet-IO (PNIO) stack versions prior to V06.00, update to version V06.00 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2020-02435
CVE-2019-13946

Affected Products

Profinet-Io