CVE-2019-10943 is a high-severity vulnerability affecting various Siemens SIMATIC S7-1200 and S7-1500 CPU families, along with other related controllers. An unauthenticated attacker with network access to port 102/tcp can modify the user program on the PLC, causing the running code to differ from the stored source code. This impacts the perceived integrity of the user program, as an engineer attempting to retrieve the code would receive an inaccurate version. The CVSS score is 7.5 (High), indicating a network-based attack with low complexity and high integrity impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention and one media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:simatic_et_200sp_open_controller_cpu_1515sp_pc_firmware:*:*:*:*:*:*:*:* | ||
< 20.8CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_et_200sp_open_controller_cpu_1515sp_pc2_firmware:*:*:*:*:*:*:*:* | ||
< 4.4CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_s7-1200_cpu_1211c_firmware:*:*:*:*:*:*:*:* | ||
< 4.4CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212c_firmware:*:*:*:*:*:*:*:* | ||
< 4.4CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214c_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.