CVE-2019-10926

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.
References
Link Resource
http://www.securityfocus.com/bid/108725 Third Party Advisory VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-816980.pdf Mitigation Vendor Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-19-162-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:simatic_mv420_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_mv420:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_mv440_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_mv440:-:*:*:*:*:*:*:*

History

15 Mar 2021, 18:15

Type Values Removed Values Added
Summary A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted. A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.

15 Mar 2021, 17:15

Type Values Removed Values Added
CWE CWE-310 CWE-319
Summary A vulnerability has been identified in SIMATIC Ident MV420 family (All versions), SIMATIC Ident MV440 family (All versions). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows evesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted. At the time of advisory publication no public exploitation of this security vulnerability was known. A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.

Information

Published : 2019-06-12 14:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-10926

Mitre link : CVE-2019-10926

CVE.ORG link : CVE-2019-10926


JSON object : View

Products Affected

siemens

  • simatic_mv420_firmware
  • simatic_mv440_firmware
  • simatic_mv440
  • simatic_mv420
CWE
CWE-319

Cleartext Transmission of Sensitive Information

CWE-310

Cryptographic Issues