Description
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit
internal resource allocation when multiple legitimate diagnostic package
requests are sent to the DCE-RPC interface.
This could lead to a denial of service condition due to lack of memory
for devices that include a vulnerable version of the stack.

The security vulnerability could be exploited by an attacker with network
access to an affected device. Successful exploitation requires no system
privileges and no user interaction. An attacker could use the vulnerability
to compromise the availability of the device.
Published: 2020-02-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-5213 Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device.
History

Fri, 20 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Siemens Dk Standard Ethernet Controller Ek-ertec 200 Ek-ertec 200 Firmware Ek-ertec 200p Ek-ertec 200p Firmware Im 154-3 Pn Hf Im 154-3 Pn Hf Firmware Im 154-4 Pn Hf Im 154-4 Pn Hf Firmware Profinet Driver Ruggedcom Rm1224 Ruggedcom Rm1224 Firmware Scalance M-800 Scalance M-800 Firmware Scalance S615 Scalance S615 Firmware Scalance W700 Ieee 802.11n Scalance W700 Ieee 802.11n Firmware Scalance X-200irt Scalance X-200irt Firmware Scalance X-300 Scalance X-300 Firmware Scalance X-400 Scalance X-400 Firmware Scalance Xb-200 Scalance Xb-200 Firmware Scalance Xc-200 Scalance Xc-200 Firmware Scalance Xf-200 Scalance Xf-200 Firmware Scalance Xf-200ba Scalance Xf-200ba Firmware Scalance Xm-400 Scalance Xm-400 Firmware Scalance Xp-200 Scalance Xp-200 Firmware Scalance Xr-300wg Scalance Xr-300wg Firmware Scalance Xr524 Scalance Xr524 Firmware Scalance Xr526 Scalance Xr526 Firmware Scalance Xr528 Scalance Xr528 Firmware Scalance Xr552 Scalance Xr552 Firmware Simatic Cp 1604 Simatic Cp 1604 Firmware Simatic Cp 1616 Simatic Cp 1616 Firmware Simatic Cp 343-1 Simatic Cp 343-1 Advanced Simatic Cp 343-1 Advanced Firmware Simatic Cp 343-1 Erpc Simatic Cp 343-1 Erpc Firmware Simatic Cp 343-1 Firmware Simatic Cp 343-1 Lean Simatic Cp 343-1 Lean Firmware Simatic Cp 443-1 Simatic Cp 443-1 Advanced Simatic Cp 443-1 Advanced Firmware Simatic Cp 443-1 Firmware Simatic Cp 443-1 Opc Ua Simatic Cp 443-1 Opc Ua Firmware Simatic Et200al Im 157-1 Pn Simatic Et200al Im 157-1 Pn Firmware Simatic Et200ecopn Simatic Et200ecopn Firmware Simatic Et200m Im153-4 Pn Io Hf Simatic Et200m Im153-4 Pn Io Hf Firmware Simatic Et200m Im153-4 Pn Io St Simatic Et200m Im153-4 Pn Io St Firmware Simatic Et200mp Im155-5 Pn Hf Simatic Et200mp Im155-5 Pn Hf Firmware Simatic Et200mp Im155-5 Pn St Simatic Et200mp Im155-5 Pn St Firmware Simatic Et200pro Simatic Et200pro Firmware Simatic Et200s Simatic Et200s Firmware Simatic Et200sp Im155-6 Pn Basic Simatic Et200sp Im155-6 Pn Basic Firmware Simatic Et200sp Im155-6 Pn Hf Simatic Et200sp Im155-6 Pn Hf Firmware Simatic Et200sp Im155-6 Pn St Simatic Et200sp Im155-6 Pn St Firmware Simatic Ipc Support Simatic Mv420 Simatic Mv420 Firmware Simatic Mv440 Simatic Mv440 Firmware Simatic Pn\/pn Coupler Simatic Pn\/pn Coupler Firmware Simatic Rf180c Simatic Rf180c Firmware Simatic Rf182c Simatic Rf182c Firmware Simatic Rf600 Simatic Rf600 Firmware Sinamics Dcp Sinamics Dcp Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-05T00:05:44.023Z

Reserved: 2019-07-18T00:00:00.000Z

Link: CVE-2019-13946

cve-icon Vulnrichment

Updated: 2024-08-05T00:05:44.023Z

cve-icon NVD

Status : Modified

Published: 2020-02-11T16:15:15.023

Modified: 2024-11-21T04:25:45.080

Link: CVE-2019-13946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses