CVE-2019-10953
Summary
| CVE | CVE-2019-10953 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-17 15:29:00 UTC |
| Updated | 2026-05-29 16:16:20 UTC |
| Description | ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.004830000 probability, percentile 0.656410000 (date 2026-06-09)
Problem Types: CWE-400 | CWE-770 | CWE-400 UNCONTROLLED RESOURCE CONSUMPTION CWE-400
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
AV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Abb | Pm554-tp-eth | - | All | All | All |
| Operating System | Abb | Pm554-tp-eth Firmware | - | All | All | All |
| Hardware | Phoenixcontact | Ilc 151 Eth | - | All | All | All |
| Operating System | Phoenixcontact | Ilc 151 Eth Firmware | - | All | All | All |
| Hardware | Schneider-electric | Modicon M221 | - | All | All | All |
| Operating System | Schneider-electric | Modicon M221 Firmware | All | All | All | All |
| Hardware | Siemens | 6ed1052-1cc01-0ba8 | - | All | All | All |
| Operating System | Siemens | 6ed1052-1cc01-0ba8 Firmware | - | All | All | All |
| Hardware | Siemens | 6es7211-1ae40-0xb0 | - | All | All | All |
| Operating System | Siemens | 6es7211-1ae40-0xb0 Firmware | - | All | All | All |
| Hardware | Siemens | 6es7314-6eh04-0ab0 | - | All | All | All |
| Operating System | Siemens | 6es7314-6eh04-0ab0 Firmware | - | All | All | All |
| Hardware | Wago | Bacnet/ip | - | All | All | All |
| Operating System | Wago | Bacnet/ip Firmware | - | All | All | All |
| Hardware | Wago | Ethernet | - | All | All | All |
| Operating System | Wago | Ethernet Firmware | - | All | All | All |
| Hardware | Wago | Knx Ip | - | All | All | All |
| Operating System | Wago | Knx Ip Firmware | - | All | All | All |
| Hardware | Wago | Pfc100 | - | All | All | All |
| Operating System | Wago | Pfc100 Firmware | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | ABB | 1SAP120600R0071 PM554-TP-ETH | affected Multiple | Not specified |
| CNA | Phoenix Contact | 2700974 ILC 151 ETH | affected Multiple | Not specified |
| CNA | Phoenix Contact | ILC 191 ETH 2TX | affected Multiple | Not specified |
| CNA | Schneider Electric | Modicon M221 | affected v1.10.0.0 custom | Not specified |
| CNA | Schneider Electric | Modicon M221 | unaffected v1.10.0.0 | Not specified |
| CNA | Schneider Electric | EcoStruxure Machine Expert Basic | affected v1.0 custom | Not specified |
| CNA | Schneider Electric | EcoStruxure Machine Expert Basic | unaffected v1.0 | Not specified |
| CNA | Siemens | 6ES7211-1AE40-0XB0 Simatic S7-1211 | unaffected Multiple | Not specified |
| CNA | Siemens | 6ES7314-6EH04-0AB0 Simatic S7-314 | unaffected Multiple | Not specified |
| CNA | Siemens | 6ED1052-1CC01-0BA8 Logo! 8 | unaffected Multiple | Not specified |
| CNA | WAGO | 750-889 Controller KNX IP | affected Multiple | Not specified |
| CNA | WAGO | 750-8100 Controller PFC100 | affected Multiple | Not specified |
| CNA | WAGO | 750-880 Controller ETH | affected Multiple | Not specified |
| CNA | WAGO | 750-831 Controller BACnet/IP | affected Multiple | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| PLC Cycle Time Influences | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Mitigation, Third Party Advisory, US Government Resource |
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2019/icsa-19-10... | https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2019/icsa-19-106-03.json | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), and Florian Fischer (Hochschule Augsburg) reported this vulnerability to CISA. (en)
CNA: Mikael Vingaard found and reported to CISA additional devices containing this vulnerability. (en)
Additional Advisory Data
Solutions
CNA: Fixes are available in Schneider Electric Modicon M221 firmware v1.10.0.0 and EcoStruxure Machine Expert – Basic v1.0 software (formerly SoMachine Basic) using either of the following options: Use this link to download the Machine Expert Basic software. Or run the Schneider Electric Software Update tool in order to download and install EcoStruxure Machine Expert – Basic v1.0 software. For additional information, see the Schneider Electric security notice SEVD-2019-045-01. (https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2019-045-01) Schneider Electric strongly recommends following industry cybersecurity best practices, such as: * Physical controls should be in place so no unauthorized person would have access to the ICS and safety controllers, peripheral equipment, or the ICS and safety networks. * All controllers should reside in locked cabinets and never be left in the “Program” mode. * All programming software should be kept in locked cabinets and should never be connected to any network other than the network for the devices it is intended. * All methods of mobile data exchange with the isolated network (e.g., CDs, USB drives, etc.) should be scanned before use in terminals or any node connected to these networks. * Laptops that have connected to any other network besides the intended network should never be allowed to connect to the safety or control networks without proper sanitation.
Workarounds
CNA: ABB concludes the reported behavior is not a vulnerability but is due to a misconfiguration of the PLC watchdog, which was left in the default factory settings. This has led to a configuration that does not match the expectations expressed in the test cases and the result is the PLC not reacting as intended. This misconfiguration can be fixed by setting an appropriate combination of task priority, task cycle time, and watchdog settings. Please see the “Onboard Ethernet Handling in CPU Firmware” chapter (System Technology for AC500 V2 Products > System Technology of CPU and Overall System > Onboard Technologies > Ethernet > Ethernet Protocols and Ports for AC500 V2 Products > Onboard Ethernet Handling in CPU Firmware) for further guidance.
CNA: Phoenix Contact acknowledges this as a “known, won’t fix” issue for old products. Currently available products provide countermeasures to mitigate the impact on the safety-related functionality. Phoenix Contact urges users to adhere to the Application note 107913_en_01. More information can be found in the VDE CERT advisory https://cert.vde.com/en-us/advisories/vde-2018-012 .
CNA: Siemens has investigated the vulnerability report on PLC cycle time influences and concludes the report does not demonstrate a valid vulnerability for Siemens PLCs.
CNA: WAGO recommends users operate the devices in closed networks or protect them with a firewall against unauthorized access. Another recommended mitigation is to limit network traffic via the switch rate limit feature according to application needs. Please also consult the product manuals on the WAGO website, as this is a known problem for some devices. Links to product manuals and specific instructions about how to limit switch rates can be found in the VDE CERT advisory https://cert.vde.com/de-de/advisories/vde-2018-013 .