Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit
internal resource allocation when multiple legitimate diagnostic package
requests are sent to the DCE-RPC interface.
This could lead to a denial of service condition due to lack of memory
for devices that include a vulnerable version of the stack.

The security vulnerability could be exploited by an attacker with network
access to an affected device. Successful exploitation requires no system
privileges and no user interaction. An attacker could use the vulnerability
to compromise the availability of the device.

Project Subscriptions

Vendors Products
Siemens Subscribe
Dk Standard Ethernet Controller Subscribe
Ek-ertec 200 Subscribe
Ek-ertec 200 Firmware Subscribe
Ek-ertec 200p Subscribe
Ek-ertec 200p Firmware Subscribe
Im 154-3 Pn Hf Subscribe
Im 154-3 Pn Hf Firmware Subscribe
Im 154-4 Pn Hf Subscribe
Im 154-4 Pn Hf Firmware Subscribe
Profinet Driver Subscribe
Ruggedcom Rm1224 Subscribe
Ruggedcom Rm1224 Firmware Subscribe
Scalance M-800 Subscribe
Scalance M-800 Firmware Subscribe
Scalance S615 Subscribe
Scalance S615 Firmware Subscribe
Scalance W700 Ieee 802.11n Subscribe
Scalance W700 Ieee 802.11n Firmware Subscribe
Scalance X-200irt Subscribe
Scalance X-200irt Firmware Subscribe
Scalance X-300 Subscribe
Scalance X-300 Firmware Subscribe
Scalance X-400 Subscribe
Scalance X-400 Firmware Subscribe
Scalance Xb-200 Subscribe
Scalance Xb-200 Firmware Subscribe
Scalance Xc-200 Subscribe
Scalance Xc-200 Firmware Subscribe
Scalance Xf-200 Subscribe
Scalance Xf-200 Firmware Subscribe
Scalance Xf-200ba Subscribe
Scalance Xf-200ba Firmware Subscribe
Scalance Xm-400 Subscribe
Scalance Xm-400 Firmware Subscribe
Scalance Xp-200 Subscribe
Scalance Xp-200 Firmware Subscribe
Scalance Xr-300wg Subscribe
Scalance Xr-300wg Firmware Subscribe
Scalance Xr524 Subscribe
Scalance Xr524 Firmware Subscribe
Scalance Xr526 Subscribe
Scalance Xr526 Firmware Subscribe
Scalance Xr528 Subscribe
Scalance Xr528 Firmware Subscribe
Scalance Xr552 Subscribe
Scalance Xr552 Firmware Subscribe
Simatic Cp 1604 Subscribe
Simatic Cp 1604 Firmware Subscribe
Simatic Cp 1616 Subscribe
Simatic Cp 1616 Firmware Subscribe
Simatic Cp 343-1 Subscribe
Simatic Cp 343-1 Advanced Subscribe
Simatic Cp 343-1 Advanced Firmware Subscribe
Simatic Cp 343-1 Erpc Subscribe
Simatic Cp 343-1 Erpc Firmware Subscribe
Simatic Cp 343-1 Firmware Subscribe
Simatic Cp 343-1 Lean Subscribe
Simatic Cp 343-1 Lean Firmware Subscribe
Simatic Cp 443-1 Subscribe
Simatic Cp 443-1 Advanced Subscribe
Simatic Cp 443-1 Advanced Firmware Subscribe
Simatic Cp 443-1 Firmware Subscribe
Simatic Cp 443-1 Opc Ua Subscribe
Simatic Cp 443-1 Opc Ua Firmware Subscribe
Simatic Et200al Im 157-1 Pn Subscribe
Simatic Et200al Im 157-1 Pn Firmware Subscribe
Simatic Et200ecopn Subscribe
Simatic Et200ecopn Firmware Subscribe
Simatic Et200m Im153-4 Pn Io Hf Subscribe
Simatic Et200m Im153-4 Pn Io Hf Firmware Subscribe
Simatic Et200m Im153-4 Pn Io St Subscribe
Simatic Et200m Im153-4 Pn Io St Firmware Subscribe
Simatic Et200mp Im155-5 Pn Hf Subscribe
Simatic Et200mp Im155-5 Pn Hf Firmware Subscribe
Simatic Et200mp Im155-5 Pn St Subscribe
Simatic Et200mp Im155-5 Pn St Firmware Subscribe
Simatic Et200pro Subscribe
Simatic Et200pro Firmware Subscribe
Simatic Et200s Subscribe
Simatic Et200s Firmware Subscribe
Simatic Et200sp Im155-6 Pn Basic Subscribe
Simatic Et200sp Im155-6 Pn Basic Firmware Subscribe
Simatic Et200sp Im155-6 Pn Hf Subscribe
Simatic Et200sp Im155-6 Pn Hf Firmware Subscribe
Simatic Et200sp Im155-6 Pn St Subscribe
Simatic Et200sp Im155-6 Pn St Firmware Subscribe
Simatic Ipc Support Subscribe
Simatic Mv420 Subscribe
Simatic Mv420 Firmware Subscribe
Simatic Mv440 Subscribe
Simatic Mv440 Firmware Subscribe
Simatic Pn\/pn Coupler Subscribe
Simatic Pn\/pn Coupler Firmware Subscribe
Simatic Rf180c Subscribe
Simatic Rf180c Firmware Subscribe
Simatic Rf182c Subscribe
Simatic Rf182c Firmware Subscribe
Simatic Rf600 Subscribe
Simatic Rf600 Firmware Subscribe
Sinamics Dcp Subscribe
Sinamics Dcp Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-5213 Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-05T00:05:44.023Z

Reserved: 2019-07-18T00:00:00

Link: CVE-2019-13946

cve-icon Vulnrichment

Updated: 2024-08-05T00:05:44.023Z

cve-icon NVD

Status : Modified

Published: 2020-02-11T16:15:15.023

Modified: 2024-11-21T04:25:45.080

Link: CVE-2019-13946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses