PT-2020-2433 · Siemens · Profinet-Io
Published
2020-02-11
·
Updated
2024-07-09
·
CVE-2019-13946
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Profinet-IO (PNIO) stack versions prior to V06.00
Description
The issue is related to an uncontrolled resource consumption in the DCE-RPC interface of Siemens hardware and software. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. An attacker with network access to an affected device can exploit this issue without requiring system privileges or user interaction, compromising the availability of the device.
Recommendations
For Profinet-IO (PNIO) stack versions prior to V06.00, update to version V06.00 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Profinet-Io