CVE-2019-6568

high-risk
Published 2019-04-17

The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.

Do I need to act?

-
0.41% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Cp1604 Firmware
Cp1616 Firmware
Simatic Rf185C Firmware
Simatic Cp343-1 Advanced Firmware
Simatic Cp443-1 Firmware
Simatic Cp443-1 Advanced Firmware
Simatic Et 200 Sp Open Controller Cpu 1515Sp Pc Firmware
Simatic Et 200 Sp Open Controller Cpu 1515Sp Pc2 Firmware
Simatic Hmi Comfort Outdoor Panels Firmware
Simatic Hmi Comfort Outdoor Panels Firmware
Simatic Hmi Comfort Panels Firmware
Simatic Hmi Comfort Panels Firmware
Simatic Hmi Ktp Mobile Panels Ktp400F Firmware
Simatic Hmi Ktp Mobile Panels Ktp400F Firmware
Simatic Hmi Ktp Mobile Panels Ktp700 Firmware
Simatic Hmi Ktp Mobile Panels Ktp700 Firmware
Simatic Hmi Ktp Mobile Panels Ktp700F Firmware
Simatic Hmi Ktp Mobile Panels Ktp700F Firmware
Simatic Hmi Ktp Mobile Panels Ktp900 Firmware
Simatic Hmi Ktp Mobile Panels Ktp900 Firmware

Affected Vendors

56
/ 100
high-risk
Severity 26/34 · High
Exploitability 2/34 · Minimal
Exposure 28/34 · Critical