PT-2020-2436 · Siemens · Simatic Route Control+5

Published

2020-02-11

·

Updated

2023-04-11

·

CVE-2019-19282

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenPCS 7 versions 8.1 through 9.0 SIMATIC BATCH versions 8.1 through 9.0 SIMATIC NET PC Software versions 14 through 16 SIMATIC PCS 7 versions 8.1 through 9.0 SIMATIC Route Control versions 8.1 through 9.0 SIMATIC WinCC (TIA Portal) versions 13 through 16 SIMATIC WinCC versions 7.3 through 7.5
Description The issue is related to a buffer restriction for downloaded data. An attacker with network access could exploit this to compromise system availability by causing a Denial-of-Service condition. Successful exploitation requires no system privileges and no user interaction.
Recommendations For OpenPCS 7 versions 8.1 through 9.0, update to a version that includes the necessary security patches. For SIMATIC BATCH versions 8.1 through 9.0, apply the recommended security updates. For SIMATIC NET PC Software versions 14 through 16, install the latest security patches. For SIMATIC PCS 7 versions 8.1 through 9.0, update to a patched version to resolve the issue. For SIMATIC Route Control versions 8.1 through 9.0, apply the necessary security fixes. For SIMATIC WinCC (TIA Portal) versions 13 through 16, update to the latest version that includes security patches. For SIMATIC WinCC versions 7.3 through 7.5, install the recommended security updates.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2020-02442
CVE-2019-19282

Affected Products

Openpcs 7
Simatic Batch
Simatic Net Pc
Simatic Pcs 7
Simatic Route Control
Simatic Wincc