CVE-2019-6568

HIGH

Siemens Cp1604 Firmware < 1.1.0 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.

Scores

CVSS v3 7.5
EPSS 0.0041
EPSS Percentile 61.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (46)
siemens/cp1604_firmware
siemens/cp1616_firmware
siemens/simatic_cp343-1_advanced_firmware
siemens/simatic_cp443-1_advanced_firmware
siemens/simatic_cp443-1_firmware
siemens/simatic_cp443-1_opc_ua
siemens/simatic_et_200_sp_open_controller_cpu_1515sp_pc2_firmware < 2.7
siemens/simatic_et_200_sp_open_controller_cpu_1515sp_pc_firmware < 2.1.6
siemens/simatic_hmi_comfort_outdoor_panels_firmware 15.1
siemens/simatic_hmi_comfort_outdoor_panels_firmware < 15.1
... and 36 more
Published Apr 17, 2019
Tracked Since Feb 18, 2026