Lucene search

K
cve[email protected]CVE-2019-10927
HistoryAug 13, 2019 - 7:15 p.m.

CVE-2019-10927

2019-08-1319:15:14
CWE-703
web.nvd.nist.gov
51
vulnerability
scalance
authenticated attacker
denial-of-service
port 22
nvd

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.2%

A vulnerability has been identified in SCALANCE SC-600 (V2.0), SCALANCE XB-200 (V4.1), SCALANCE XC-200 (V4.1), SCALANCE XF-200BA (V4.1), SCALANCE XP-200 (V4.1), SCALANCE XR-300WG (V4.1). An authenticated attacker with network access to to port 22/tcp of an affected device may cause a Denial-of-Service condition. The security vulnerability could be exploited by an authenticated attacker with network access to the affected device. No user interaction is required to exploit this vulnerability. The vulnerability impacts the availability of the affected device.

Affected configurations

NVD
Node
siemensscalance_xb-200_firmwareMatch4.1
AND
siemensscalance_xb-200Match-
Node
siemensscalance_xc-200_firmwareMatch4.1
AND
siemensscalance_xc-200Match-
Node
siemensscalance_xf-200ba_firmwareMatch4.1
AND
siemensscalance_xf-200baMatch-
Node
siemensscalance_xp-200_firmwareMatch4.1
AND
siemensscalance_xp-200Match-
Node
siemensscalance_xr-300wg_firmwareMatch4.1
AND
siemensscalance_xr-300wgMatch-

CNA Affected

[
  {
    "product": "SCALANCE SC-600",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V2.0"
      }
    ]
  },
  {
    "product": "SCALANCE XB-200",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V4.1"
      }
    ]
  },
  {
    "product": "SCALANCE XC-200",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V4.1"
      }
    ]
  },
  {
    "product": "SCALANCE XF-200BA",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V4.1"
      }
    ]
  },
  {
    "product": "SCALANCE XP-200",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V4.1"
      }
    ]
  },
  {
    "product": "SCALANCE XR-300WG",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V4.1"
      }
    ]
  }
]

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.2%