Description
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.
References (2)
Core 2
Core References
Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-480230.pdf
Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdf
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
61.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (46)
siemens/cp1604_firmware
siemens/cp1616_firmware
siemens/simatic_cp343-1_advanced_firmware
siemens/simatic_cp443-1_advanced_firmware
siemens/simatic_cp443-1_firmware
siemens/simatic_cp443-1_opc_ua
siemens/simatic_et_200_sp_open_controller_cpu_1515sp_pc2_firmware
< 2.7
siemens/simatic_et_200_sp_open_controller_cpu_1515sp_pc_firmware
< 2.1.6
siemens/simatic_hmi_comfort_outdoor_panels_firmware
15.1
siemens/simatic_hmi_comfort_outdoor_panels_firmware
< 15.1
... and 36 more
Published
Apr 17, 2019
Tracked Since
Feb 18, 2026