Vulnerability Details CVE-2019-10926
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 56.9%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 2.6
Products affected by CVE-2019-10926
-
cpe:2.3:h:siemens:simatic_mv420:-
-
cpe:2.3:h:siemens:simatic_mv440:-
-
cpe:2.3:o:siemens:simatic_mv420_firmware:-
-
cpe:2.3:o:siemens:simatic_mv440_firmware:-