A vulnerability has been identified in SIMATIC ET 200pro IM154-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8F PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8FX PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200S IM151-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200S IM151-8F PN/DP CPU (All versions < V3.X.17), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.1), SIMATIC S7-300 CPU 314C-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 315-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 315F-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 315T-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317F-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317T-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317TF-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 319-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 319F-3 PN/DP (All versions < V3.X.17), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX 2010 (All versions), SIMATIC WinAC RTX F 2010 (All versions), SIPLUS ET 200S IM151-8 PN/DP CPU (All versions < V3.X.17), SIPLUS ET 200S IM151-8F PN/DP CPU (All versions < V3.X.17), SIPLUS S7-300 CPU 314C-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 315-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 315F-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 317-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 317F-2 PN/DP (All versions < V3.X.17). Affected devices contain a vulnerability that could cause a denial of service condition of the web server
by sending specially crafted HTTP requests to ports 80/tcp and 443/tcp.

Beyond the web service, no other functions or interfaces are affected by the denial of service condition.

Project Subscriptions

Vendors Products
Siemens Subscribe
S7-1200 Cpu 1211c Subscribe
S7-1200 Cpu 1211c Firmware Subscribe
S7-1200 Cpu 1212c Subscribe
S7-1200 Cpu 1212c Firmware Subscribe
S7-1200 Cpu 1212fc Subscribe
S7-1200 Cpu 1212fc Firmware Subscribe
S7-1200 Cpu 1214c Subscribe
S7-1200 Cpu 1214c Firmware Subscribe
S7-1200 Cpu 1214fc Subscribe
S7-1200 Cpu 1214fc Firmware Subscribe
S7-1200 Cpu 1215c Subscribe
S7-1200 Cpu 1215c Firmware Subscribe
S7-1200 Cpu 1215fc Subscribe
S7-1200 Cpu 1215fc Firmware Subscribe
S7-1200 Cpu 1217c Subscribe
S7-1200 Cpu 1217c Firmware Subscribe
Simatic S7-300 Cpu 315-2 Pn\/dp Subscribe
Simatic S7-300 Cpu 315-2 Pn\/dp Firmware Subscribe
Simatic S7-300 Cpu 315-2dp Subscribe
Simatic S7-300 Cpu 315-2dp Firmware Subscribe
Simatic S7-300 Cpu 317-2 Dp Subscribe
Simatic S7-300 Cpu 317-2 Dp Firmware Subscribe
Simatic S7-300 Cpu 317-2 Pn\/dp Subscribe
Simatic S7-300 Cpu 317-2 Pn\/dp Firmware Subscribe
Simatic S7-300 Cpu 319-3 Pn\/dp Subscribe
Simatic S7-300 Cpu 319-3 Pn\/dp Firmware Subscribe
Simatic S7-400 Pn\/dp Cpu Subscribe
Simatic S7-400 Pn\/dp Cpu Firmware Subscribe
Simatic Winac Rtx \(f\) 2010 Subscribe
Siplus Cpu 1211c Subscribe
Siplus Cpu 1211c Firmware Subscribe
Siplus Cpu 1212c Subscribe
Siplus Cpu 1212c Firmware Subscribe
Siplus Cpu 1214c Subscribe
Siplus Cpu 1214c Firmware Subscribe
Siplus Cpu 1215c Subscribe
Siplus Cpu 1215c Firmware Subscribe
Siplus S7-1200 Subscribe
Siplus S7-1200 Firmware Subscribe
Siplus S7-300 Cpu 314 Subscribe
Siplus S7-300 Cpu 314 Firmware Subscribe
Siplus S7-300 Cpu 315-2 Dp Subscribe
Siplus S7-300 Cpu 315-2 Dp Firmware Subscribe
Siplus S7-300 Cpu 315-2 Pn\/dp Subscribe
Siplus S7-300 Cpu 315-2 Pn\/dp Firmware Subscribe
Siplus S7-300 Cpu 317-2 Pn\/dp Subscribe
Siplus S7-300 Cpu 317-2 Pn\/dp Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-5207 A vulnerability has been identified in SIMATIC ET 200pro IM154-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8F PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8FX PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200S IM151-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200S IM151-8F PN/DP CPU (All versions < V3.X.17), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.1), SIMATIC S7-300 CPU 314C-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 315-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 315F-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 315T-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317F-2 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317T-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 317TF-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 319-3 PN/DP (All versions < V3.X.17), SIMATIC S7-300 CPU 319F-3 PN/DP (All versions < V3.X.17), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX 2010 (All versions), SIMATIC WinAC RTX F 2010 (All versions), SIPLUS ET 200S IM151-8 PN/DP CPU (All versions < V3.X.17), SIPLUS ET 200S IM151-8F PN/DP CPU (All versions < V3.X.17), SIPLUS S7-300 CPU 314C-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 315-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 315F-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 317-2 PN/DP (All versions < V3.X.17), SIPLUS S7-300 CPU 317F-2 PN/DP (All versions < V3.X.17). Affected devices contain a vulnerability that could cause a denial of service condition of the web server by sending specially crafted HTTP requests to ports 80/tcp and 443/tcp. Beyond the web service, no other functions or interfaces are affected by the denial of service condition.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-05T00:05:44.018Z

Reserved: 2019-07-18T00:00:00

Link: CVE-2019-13940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-11T16:15:14.773

Modified: 2024-11-21T04:25:44.283

Link: CVE-2019-13940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses