CVE-2019-10925
Summary
| CVE | CVE-2019-10925 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-12 14:29:00 UTC |
| Updated | 2021-03-15 18:15:00 UTC |
| Description | A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by sending specially crafted requests to the integrated webserver. The security vulnerability can be exploited by an attacker with network access to the device. Valid user credentials, but no user interaction are required. Successful exploitation compromises integrity and availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Simatic Mv420 | - | All | All | All |
| Hardware | Siemens | Simatic Mv420 | - | All | All | All |
| Operating System | Siemens | Simatic Mv420 Firmware | All | All | All | All |
| Operating System | Siemens | Simatic Mv420 Firmware | All | All | All | All |
| Hardware | Siemens | Simatic Mv440 | - | All | All | All |
| Hardware | Siemens | Simatic Mv440 | - | All | All | All |
| Operating System | Siemens | Simatic Mv440 Firmware | All | All | All | All |
| Operating System | Siemens | Simatic Mv440 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Siemens SIMATIC Ident MV420 and MV440 Families Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| cert-portal.siemens.com/productcert/pdf/ssa-816980.pdf | MISC | cert-portal.siemens.com | Mitigation, Vendor Advisory |
| Siemens SIMATIC Ident MV420 and MV440 Families | CISA | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.