Vulnerability Details CVE-2019-19301
A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT, SCALANCE X202-2P IRT PRO, SCALANCE X204-2, SCALANCE X204-2FM, SCALANCE X204-2LD, SCALANCE X204-2LD TS, SCALANCE X204-2TS, SCALANCE X204IRT, SCALANCE X204IRT PRO, SCALANCE X206-1, SCALANCE X206-1LD, SCALANCE X208, SCALANCE X208PRO, SCALANCE X212-2, SCALANCE X212-2LD, SCALANCE X216, SCALANCE X224, SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (2x 230V, coated), SCALANCE X307-2 EEC (2x 230V), SCALANCE X307-2 EEC (2x 24V, coated), SCALANCE X307-2 EEC (2x 24V), SCALANCE X307-3, SCALANCE X307-3, SCALANCE X307-3LD, SCALANCE X307-3LD, SCALANCE X308-2, SCALANCE X308-2, SCALANCE X308-2LD, SCALANCE X308-2LD, SCALANCE X308-2LH, SCALANCE X308-2LH, SCALANCE X308-2LH+, SCALANCE X308-2LH+, SCALANCE X308-2M, SCALANCE X308-2M, SCALANCE X308-2M PoE, SCALANCE X308-2M PoE, SCALANCE X308-2M TS, SCALANCE X308-2M TS, SCALANCE X310, SCALANCE X310, SCALANCE X310FE, SCALANCE X310FE, SCALANCE X320-1 FE, SCALANCE X320-1-2LD FE, SCALANCE X408-2, SCALANCE XF201-3P IRT, SCALANCE XF202-2P IRT, SCALANCE XF204, SCALANCE XF204-2, SCALANCE XF204-2BA IRT, SCALANCE XF204IRT, SCALANCE XF206-1, SCALANCE XF208, SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M TS (24V), SCALANCE XR324-12M TS (24V), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M PoE (230V, ports on front), SCALANCE XR324-4M PoE (230V, ports on rear), SCALANCE XR324-4M PoE (24V, ports on front), SCALANCE XR324-4M PoE (24V, ports on rear), SCALANCE XR324-4M PoE TS (24V, ports on front), SIMATIC CP 343-1 Advanced, SIMATIC CP 442-1 RNA, SIMATIC CP 443-1, SIMATIC CP 443-1, SIMATIC CP 443-1 Advanced, SIMATIC CP 443-1 RNA, SIMATIC RF180C, SIMATIC RF182C, SIPLUS NET CP 343-1 Advanced, SIPLUS NET CP 443-1, SIPLUS NET CP 443-1 Advanced, SIPLUS NET SCALANCE X308-2. The VxWorks-based Profinet TCP Stack can be forced to make very expensive calls for every incoming packet which can lead to a denial of service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-19301
-
cpe:2.3:h:siemens:scalance_x-200irt:-
-
cpe:2.3:h:siemens:scalance_x-200irt_pro:-
-
cpe:2.3:h:siemens:scalance_x-300:-
-
cpe:2.3:h:siemens:scalance_xb-200:-
-
cpe:2.3:h:siemens:scalance_xc-200:-
-
cpe:2.3:h:siemens:scalance_xf-200:-
-
cpe:2.3:h:siemens:scalance_xp-200:-
-
cpe:2.3:h:siemens:scalance_xr-300:-
-
cpe:2.3:h:siemens:scalance_xr-300wg:-
-
cpe:2.3:h:siemens:simatic_cp_443-1:-
-
cpe:2.3:h:siemens:simatic_cp_443-1_advanced:-
-
cpe:2.3:h:siemens:simatic_rf180c:-
-
cpe:2.3:h:siemens:simatic_rf182c:-
-
cpe:2.3:o:siemens:scalance_x-200irt_firmware:-
-
cpe:2.3:o:siemens:scalance_x-200irt_firmware:5.2.1
-
cpe:2.3:o:siemens:scalance_x-200irt_firmware:5.3
-
cpe:2.3:o:siemens:scalance_x-200irt_firmware:5.4.2
-
cpe:2.3:o:siemens:scalance_x-200irt_pro_firmware:-
-
cpe:2.3:o:siemens:scalance_x-300_firmware:-
-
cpe:2.3:o:siemens:scalance_x-300_firmware:4.1.3
-
cpe:2.3:o:siemens:scalance_xb-200_firmware:-
-
cpe:2.3:o:siemens:scalance_xb-200_firmware:3.0
-
cpe:2.3:o:siemens:scalance_xb-200_firmware:4.1
-
cpe:2.3:o:siemens:scalance_xb-200_firmware:4.3
-
cpe:2.3:o:siemens:scalance_xb-200_firmware:5.2.4
-
cpe:2.3:o:siemens:scalance_xc-200_firmware:-
-
cpe:2.3:o:siemens:scalance_xc-200_firmware:3.0
-
cpe:2.3:o:siemens:scalance_xc-200_firmware:4.1
-
cpe:2.3:o:siemens:scalance_xc-200_firmware:4.3
-
cpe:2.3:o:siemens:scalance_xc-200_firmware:5.2.4
-
cpe:2.3:o:siemens:scalance_xf-200_firmware:-
-
cpe:2.3:o:siemens:scalance_xf-200_firmware:4.1
-
cpe:2.3:o:siemens:scalance_xf-200_firmware:5.2.4
-
cpe:2.3:o:siemens:scalance_xp-200_firmware:-
-
cpe:2.3:o:siemens:scalance_xp-200_firmware:3.0
-
cpe:2.3:o:siemens:scalance_xp-200_firmware:4.1
-
cpe:2.3:o:siemens:scalance_xp-200_firmware:4.3
-
cpe:2.3:o:siemens:scalance_xp-200_firmware:5.2.4
-
cpe:2.3:o:siemens:scalance_xr-300_firmware:-
-
cpe:2.3:o:siemens:scalance_xr-300_firmware:4.1.3
-
cpe:2.3:o:siemens:scalance_xr-300wg_firmware:-
-
cpe:2.3:o:siemens:scalance_xr-300wg_firmware:3.0
-
cpe:2.3:o:siemens:scalance_xr-300wg_firmware:4.1
-
cpe:2.3:o:siemens:scalance_xr-300wg_firmware:4.1.3
-
cpe:2.3:o:siemens:scalance_xr-300wg_firmware:4.3
-
cpe:2.3:o:siemens:simatic_cp_443-1_advanced_firmware:-
-
cpe:2.3:o:siemens:simatic_cp_443-1_advanced_firmware:3.3
-
cpe:2.3:o:siemens:simatic_cp_443-1_firmware:-
-
cpe:2.3:o:siemens:simatic_cp_443-1_firmware:3.3
-
cpe:2.3:o:siemens:simatic_rf180c_firmware:-
-
cpe:2.3:o:siemens:simatic_rf182c_firmware:-