Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10939

Опубликовано: 14 апр. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 6.8
EPSS Низкий

Описание

A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3), TIM 4R-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 4R-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3). The affected versions contain an open debug port that is available under certain specific conditions. The vulnerability is only available if the IP address is configured to 192.168.1.2. If available, the debug port could be exploited by an attacker with network access to the device. No user interaction is required to exploit this vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the affected device. At the stage of publishing this security advisory no public exploitation is known.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:siemens:tim_3v-ie_firmware:*:*:*:*:*:*:*:*
Версия до 2.8 (исключая)
cpe:2.3:h:siemens:tim_3v-ie:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:siemens:tim_3v-ie_advanced_firmware:*:*:*:*:*:*:*:*
Версия до 2.8 (исключая)
cpe:2.3:h:siemens:tim_3v-ie_advanced:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:siemens:tim_4r-ie_firmware:*:*:*:*:*:*:*:*
Версия до 3.3 (исключая)
cpe:2.3:h:siemens:tim_4r-ie:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:siemens:tim_3v-ie_dnp3_firmware:*:*:*:*:*:*:*:*
Версия до 2.8 (исключая)
cpe:2.3:h:siemens:tim_3v-ie_dnp3:-:*:*:*:*:*:*:*
Конфигурация 5

Одновременно

cpe:2.3:o:siemens:tim_4r-ie_dnp3_firmware:*:*:*:*:*:*:*:*
Версия до 3.3 (исключая)
cpe:2.3:h:siemens:tim_4r-ie_dnp3:-:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.00444
Низкий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-489
NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3), TIM 4R-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 4R-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3). The affected versions contain an open debug port that is available under certain specific conditions. The vulnerability is only available if the IP address is configured to 192.168.1.2. If available, the debug port could be exploited by an attacker with network access to the device. No user interaction is required to exploit this vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the affected device. At the stage of publishing this security advisory no public exploitation is known.

EPSS

Процентиль: 63%
0.00444
Низкий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-489
NVD-CWE-Other