QID 591303

Date Published: 2023-02-03

QID 591303: "B and R" PROFINET IO Devices Denial of Service (DoS) Vulnerability (1622986485635)

AFFECTED PRODUCTS
X20IF10E3-1: All versions prior to 1.8
X20cIF10E3-1: All versions prior to 1.8
5ACPCI.XPNS-00: All versions 1.5.1 and prior

QID Detection Logic:
This QID checks for the Vulnerable version of "B and R" PROFINET IO Devices using passive scanning

Improper buffer restrictions in in PROFINET I/O of B and R Industrial Automation products X20IF10E3-1 revisions prior to 1.8, 20cIF10E3-1 revisions prior to 1.8 and 5ACPCI.XPNS-00 revision 1.5.1.0 and prior revisions may allow unauthenticated and network-based attackers to potentially enable a denial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to B and R MITIGATIONS section 1622986485635 for affected packages and patching details.

    CVEs related to QID 591303

    Software Advisories
    Advisory ID Software Component Link
    1622986485635 URL Logo www.br-automation.com/downloads_br_productcatalogue/assets/1622986485635-en-original-1.0.pdf