Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-6571

Опубликовано: 12 июн. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). An attacker with network access to port 10005/tcp of the LOGO! device could cause a Denial-of-Service condition by sending specially crafted packets. The security vulnerability could be exploited by an unauthenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:siemens:logo\!8_firmware:*:*:*:*:*:*:*:*
Версия от 1.80.00 (включая) до 1.81.00 (включая)
cpe:2.3:h:siemens:logo\!8:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:siemens:logo\!8_firmware:*:*:*:*:*:*:*:*
Версия до 1.82.00 (исключая)
cpe:2.3:h:siemens:logo\!8:-:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00193
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-119
CWE-119

Связанные уязвимости

github
больше 3 лет назад

A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). An attacker with network access to port 10005/tcp of the LOGO! device could cause a Denial-of-Service condition by sending specially crafted packets. The security vulnerability could be exploited by an unauthenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость микропрограммного обеспечения программируемого логического контроллера SIEMENS LOGO!8, связанная с неправильным контролем доступа, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость микропрограммного обеспечения устройства SIEMENS LOGO!8, связанная с неправильным контролем доступа, позволяющая нарушителю получить доступ к устройству

EPSS

Процентиль: 41%
0.00193
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-119
CWE-119