CVE-2019-19301 describes a denial-of-service vulnerability affecting numerous Siemens SCALANCE and SIMATIC industrial devices, specifically within their VxWorks-based Profinet TCP Stack. An unauthenticated attacker can exploit this by sending specially crafted network packets, forcing the device to execute resource-intensive operations. This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating a network-based attack with low complexity that can lead to a complete denial of service. While no public exploit code or Metasploit modules are available, the vulnerability has received some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:scalance_xf-200_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:* | ||
< 5.5.0CPE matchmatch criteria | cpe:2.3:o:siemens:scalance_x-200irt_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.