A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server (All firmware versions < V6.00.320). The device contains a vulnerability that could allow an attacker to cause a denial of service condition on the device's web server by sending a specially crafted HTTP message to the web server port (tcp/80). The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device's web service. While the device itself stays operational, the web server responds with HTTP status code 404 (Not found) to any further request. A reboot is required to recover the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Siemens
Subscribe
|
Pxa30-w0
Subscribe
Pxa30-w0 Firmware
Subscribe
Pxa30-w1
Subscribe
Pxa30-w1 Firmware
Subscribe
Pxa30-w2
Subscribe
Pxa30-w2 Firmware
Subscribe
Pxa40-w0
Subscribe
Pxa40-w0 Firmware
Subscribe
Pxa40-w1
Subscribe
Pxa40-w1 Firmware
Subscribe
Pxa40-w2
Subscribe
Pxa40-w2 Firmware
Subscribe
Pxc00-e.d
Subscribe
Pxc00-e.d Firmware
Subscribe
Pxc00-u
Subscribe
Pxc00-u Firmware
Subscribe
Pxc100-e.d
Subscribe
Pxc100-e.d Firmware
Subscribe
Pxc128-u
Subscribe
Pxc128-u Firmware
Subscribe
Pxc200-e.d
Subscribe
Pxc200-e.d Firmware
Subscribe
Pxc22.1-e.d
Subscribe
Pxc22.1-e.d Firmware
Subscribe
Pxc36-e.d
Subscribe
Pxc36-e.d Firmware
Subscribe
Pxc36.1-e.d
Subscribe
Pxc36.1-e.d Firmware
Subscribe
Pxc50-e.d
Subscribe
Pxc50-e.d Firmware
Subscribe
Pxc64-u
Subscribe
Pxc64-u Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-5197 | A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server (All firmware versions < V6.00.320). The device contains a vulnerability that could allow an attacker to cause a denial of service condition on the device's web server by sending a specially crafted HTTP message to the web server port (tcp/80). The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device's web service. While the device itself stays operational, the web server responds with HTTP status code 404 (Not found) to any further request. A reboot is required to recover the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-05T00:05:43.819Z
Reserved: 2019-07-18T00:00:00
Link: CVE-2019-13927
No data.
Status : Modified
Published: 2019-12-12T14:15:14.897
Modified: 2024-11-21T04:25:42.927
Link: CVE-2019-13927
No data.
OpenCVE Enrichment
No data.
EUVD