PT-2020-2437 · Siemens · En100+2

Published

2020-02-11

·

Updated

2020-03-13

·

CVE-2019-19279

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions)
Description The issue is related to insufficient input validation, which can be exploited by sending specially crafted packets to the port 50000/UDP endpoint. This can cause a Denial-of-Service, requiring a manual reboot to recover the device's service. At the time of reporting, there were no known public exploits of this security issue.
Recommendations For SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules, restrict access to the port 50000/UDP endpoint to minimize the risk of exploitation. As a temporary workaround, consider implementing network traffic filtering to block specially crafted packets sent to this endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02443
CVE-2019-19279

Affected Products

En100
Siprotec 4
Siprotec Compact