CVE-2019-13927 describes a denial-of-service vulnerability affecting Siemens Desigo PX automation controllers with specific web modules and firmware versions prior to V6.00.320. An unauthenticated attacker with network access can send a specially crafted HTTP message to the device's web server, causing it to become unresponsive and return 404 errors, requiring a reboot for recovery. Rated 5.3 MEDIUM, this vulnerability is easily exploitable with no privileges or user interaction needed, though it only impacts the web server's availability, not the device's core operations. There is no known public exploitation, exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.00.320CPE matchmatch criteria | cpe:2.3:o:siemens:pxc00-e.d_firmware:*:*:*:*:*:*:*:* | ||
< 6.00.320CPE matchmatch criteria | cpe:2.3:o:siemens:pxc50-e.d_firmware:*:*:*:*:*:*:*:* | ||
< 6.00.320CPE matchmatch criteria | cpe:2.3:o:siemens:pxc100-e.d_firmware:*:*:*:*:*:*:*:* | ||
< 6.00.320CPE matchmatch criteria | cpe:2.3:o:siemens:pxc200-e.d_firmware:*:*:*:*:*:*:*:* | ||
< 6.00.320CPE matchmatch criteria | cpe:2.3:o:siemens:pxa40-w0_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.