SSA-232418 PUBLISHED CVSS 3.700000047683716 LOW

Two vulnerabilities have been identified in the SIMATIC S7-1200/S7-1500 CPU families and related products. One vulnerability (CVE-2019-10943) could allow an attacker with network access to affected devices to modify the user program stored on these devices such that the source code differs from the actual running code. The other vulnerability (CVE-2019-10929) could allow an attacker in a Man- in-the-Middle position to modify network traffic exchanged on port 102/tcp. Siemens has released updates for several affected products to fix CVE-2019-10929 and recommends to update to the latest versions. Regarding CVE-2019-10943, Siemens recommends specific countermeasures for products where updates are not, or not yet available.

Risk Scores

CVSS v3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C

Affected Products

VendorProductVersions
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)
SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants)
SIMATIC S7-PLCSIM Advanced
SIMATIC Drive Controller family
SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
SIMATIC S7-1500 Software Controller

Timeline

References

Open in Interactive Console →