CVE-2019-13939

Published on: 01/16/2020 12:00:00 AM UTC

Last Modified on: 05/09/2023 04:27:00 PM UTC

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Certain versions of Apogee Modular Building Controller from Siemens contain the following vulnerability:

A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Series (BACnet) (All versions < V3.5.3), APOGEE PXC Series (P2) (All versions >= V2.8.2 and < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC00-U (All versions >= V2.3x and < V6.00.327), Desigo PXC001-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC100-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC12-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC128-U (All versions >= V2.3x and < V6.00.327), Desigo PXC200-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC22-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC22.1-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC36.1-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC50-E.D (All versions >= V2.3x and < V6.00.327), Desigo PXC64-U (All versions >= V2.3x and < V6.00.327), Desigo PXM20-E (All versions >= V2.3x and < V6.00.327), Nucleus NET (All versions), Nucleus RTOS (All versions), Nucleus ReadyStart for ARM, MIPS, and PPC (All versions < V2017.02.2 with patch "Nucleus 2017.02.02 Nucleus NET Patch"), Nucleus SafetyCert (All versions), Nucleus Source Code (All versions), SIMOTICS CONNECT 400 (All versions < V0.3.0.330), TALON TC Series (BACnet) (All versions < V3.5.3), VSTAR (All versions). By sending specially crafted DHCP packets to a device where the DHCP client is enabled, an attacker could change the IP address of the device to an invalid value. The vulnerability could affect availability and integrity of the device. Adjacent network access is required, but no authentication and no user interaction is needed to conduct an attack.

  • CVE-2019-13939 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.1 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
ADJACENT_NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE LOW HIGH

CVSS2 Score: 4.8 - MEDIUM

Access
Vector
Access
Complexity
Authentication
ADJACENT_NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE PARTIAL PARTIAL

CVE References

Description Tags Link
Siemens SIMOTICS, Desigo, APOGEE, and TALON | CISA us-cert.cisa.gov
text/html
URL Logo MISC us-cert.cisa.gov/ics/advisories/icsa-20-105-06
Vendor Advisory
cert-portal.siemens.com
application/pdf
URL Logo MISC cert-portal.siemens.com/productcert/pdf/ssa-434032.pdf
Vendor Advisory
cert-portal.siemens.com
application/pdf
URL Logo CONFIRM cert-portal.siemens.com/productcert/pdf/ssa-162506.pdf

Related QID Numbers

  • 590707 Siemens SIMOTICS, Desigo, APOGEE, and TALON (Update B) Vulnerability (ICSA-20-105-06)

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Hardware Device InfoSiemensApogee Modular Building Controller-AllAllAll
Hardware Device InfoSiemensApogee Modular Building Controller-AllAllAll
Operating
System
SiemensApogee Modular Building Controller FirmwareAllAllAllAll
Operating
System
SiemensApogee Modular Building Controller FirmwareAllAllAllAll
Hardware Device InfoSiemensApogee Modular Equiment Controller-AllAllAll
Hardware Device InfoSiemensApogee Modular Equiment Controller-AllAllAll
Operating
System
SiemensApogee Modular Equiment Controller FirmwareAllAllAllAll
Operating
System
SiemensApogee Modular Equiment Controller FirmwareAllAllAllAll
Hardware Device InfoSiemensApogee Pxc-AllAllAll
Hardware Device InfoSiemensApogee Pxc-AllAllAll
Operating
System
SiemensApogee Pxc FirmwareAllAllAllAll
ApplicationSiemensCapital VstarAllAllAllAll
Hardware Device InfoSiemensDesigopxc100-e.d-AllAllAll
Operating
System
SiemensDesigopxc100-e.d Firmware-AllAllAll
Hardware Device InfoSiemensDesigopxc128-u-AllAllAll
Operating
System
SiemensDesigopxc128-u Firmware-AllAllAll
Hardware Device InfoSiemensDesigopxc200-e.d-AllAllAll
Operating
System
SiemensDesigopxc200-e.d Firmware-AllAllAll
Hardware Device InfoSiemensDesigopxc50-e.d-AllAllAll
Operating
System
SiemensDesigopxc50-e.d Firmware-AllAllAll
Hardware Device InfoSiemensDesigopxc64-u-AllAllAll
Operating
System
SiemensDesigopxc64-u Firmware-AllAllAll
Hardware Device InfoSiemensDesigopxm20-e-AllAllAll
Operating
System
SiemensDesigopxm20-e Firmware-AllAllAll
Hardware Device InfoSiemensDesigo Pxc-AllAllAll
Hardware Device InfoSiemensDesigo Pxc-AllAllAll
Hardware Device InfoSiemensDesigo Pxc00-e.d-AllAllAll
Operating
System
SiemensDesigo Pxc00-e.d FirmwareAllAllAllAll
Hardware Device InfoSiemensDesigo Pxc00-u-AllAllAll
Operating
System
SiemensDesigo Pxc00-u FirmwareAllAllAllAll
Hardware Device InfoSiemensDesigo Pxc001-e.d-AllAllAll
Operating
System
SiemensDesigo Pxc001-e.d FirmwareAllAllAllAll
Hardware Device InfoSiemensDesigo Pxc12-e.d-AllAllAll
Operating
System
SiemensDesigo Pxc12-e.d FirmwareAllAllAllAll
Hardware Device InfoSiemensDesigo Pxc22-e.d-AllAllAll
Operating
System
SiemensDesigo Pxc22-e.d FirmwareAllAllAllAll
Hardware Device InfoSiemensDesigo Pxc22.1-e.d-AllAllAll
Operating
System
SiemensDesigo Pxc22.1-e.d FirmwareAllAllAllAll
Hardware Device InfoSiemensDesigo Pxc36.1-e.d-AllAllAll
Operating
System
SiemensDesigo Pxc36.1-e.d FirmwareAllAllAllAll
Operating
System
SiemensDesigo Pxc FirmwareAllAllAllAll
Operating
System
SiemensDesigo Pxc FirmwareAllAllAllAll
Hardware Device InfoSiemensDesigo Pxm20-AllAllAll
Hardware Device InfoSiemensDesigo Pxm20-AllAllAll
Operating
System
SiemensDesigo Pxm20 FirmwareAllAllAllAll
Operating
System
SiemensDesigo Pxm20 FirmwareAllAllAllAll
ApplicationSiemensNucleus NetAllAllAllAll
ApplicationSiemensNucleus NetAllAllAllAll
ApplicationSiemensNucleus ReadystartAllAllAllAll
ApplicationSiemensNucleus ReadystartAllAllAllAll
Operating
System
SiemensNucleus RtosAllAllAllAll
Operating
System
SiemensNucleus RtosAllAllAllAll
ApplicationSiemensNucleus SafetycertAllAllAllAll
ApplicationSiemensNucleus SafetycertAllAllAllAll
ApplicationSiemensNucleus Source CodeAllAllAllAll
ApplicationSiemensNucleus Source CodeAllAllAllAll
Hardware Device InfoSiemensSimotics Connect 400-AllAllAll
Hardware Device InfoSiemensSimotics Connect 400-AllAllAll
Operating
System
SiemensSimotics Connect 400 FirmwareAllAllAllAll
Hardware Device InfoSiemensTalon Tc-AllAllAll
Hardware Device InfoSiemensTalon Tc-AllAllAll
Operating
System
SiemensTalon Tc FirmwareAllAllAllAll
Operating
System
SiemensTalon Tc FirmwareAllAllAllAll
ApplicationSiemensVstarAllAllAllAll
ApplicationSiemensVstarAllAllAllAll
  • cpe:2.3:h:siemens:apogee_modular_building_controller:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:apogee_modular_building_controller:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:apogee_modular_building_controller_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:apogee_modular_building_controller_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:apogee_modular_equiment_controller:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:apogee_modular_equiment_controller:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:apogee_modular_equiment_controller_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:apogee_modular_equiment_controller_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:apogee_pxc:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:apogee_pxc:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:apogee_pxc_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:capital_vstar:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigopxc100-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigopxc100-e.d_firmware:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigopxc128-u:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigopxc128-u_firmware:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigopxc200-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigopxc200-e.d_firmware:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigopxc50-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigopxc50-e.d_firmware:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigopxc64-u:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigopxc64-u_firmware:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigopxm20-e:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigopxm20-e_firmware:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc00-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc00-e.d_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc00-u:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc00-u_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc001-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc001-e.d_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc12-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc12-e.d_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc22-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc22-e.d_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc22.1-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc22.1-e.d_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxc36.1-e.d:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc36.1-e.d_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxc_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxm20:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:desigo_pxm20:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxm20_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:desigo_pxm20_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_net:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_net:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_readystart:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_readystart:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:nucleus_rtos:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:nucleus_rtos:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_safetycert:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_safetycert:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_source_code:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:nucleus_source_code:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:simotics_connect_400:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:simotics_connect_400:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:simotics_connect_400_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:talon_tc:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:siemens:talon_tc:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:talon_tc_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:siemens:talon_tc_firmware:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:vstar:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:siemens:vstar:*:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report