- Description
- A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). Affected applications contains a memory corruption vulnerability while parsing specially crafted HTTP packets to /txtrace endpoint. This could allow an attacker to crash the affected application leading to a denial of service condition.
- Source
- productcert@siemens.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:C
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:en100_ethernet_module_dnp3_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15E8060A-2897-4E2E-9441-5687D923C642"
},
{
"criteria": "cpe:2.3:o:siemens:en100_ethernet_module_iec_104_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "300FAA93-3BBB-4848-AFA5-97DE57053E5E"
},
{
"criteria": "cpe:2.3:o:siemens:en100_ethernet_module_iec_61850_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2DB9E56-0D15-4FCA-8D1C-6C4C8EB407CF",
"versionEndExcluding": "4.37"
},
{
"criteria": "cpe:2.3:o:siemens:en100_ethernet_module_modbus_tcp_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71DCD4E3-9BA4-44CE-BFCC-6659258FCE31"
},
{
"criteria": "cpe:2.3:o:siemens:en100_ethernet_module_profinet_io_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C2FA062-EBFE-457F-988E-60A9317212A4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:en100_ethernet_module:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DAC429FD-7148-4A68-AA81-8FBADA588F4E"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]