Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-13945

Quick assessment

Affected
Siemens AG SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Siemens SIMATIC S7-200 Smart和Siemens SIMATIC S7-1200都是德国西门子(Siemens)公司的产品。Siemens SIMATIC S7-200 Smart是一款应用于中小型自动化系统中的可编程逻辑控制器(PLC)。Siemens SIMATIC S7-1200是一款S7-1200系列PLC(可编程逻辑控制器)。 Siemens S7-1200和SIMATIC S7-200中存在输入验证错误漏洞。攻击者可利用该漏洞访问其他诊断功能绕过安全限制,影响系统的完整

AI Predicted 5.3 Difficulty: Hard EPSS 0.53% · P43
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-13945

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-1200 CPU family < V4.x (incl. SIPLUS variants) (All versions), SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) (All versions with Function State (FS) < 11), SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA1) (All versions <= V2.3.0 and Function State (FS) <= 3), SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA1) (All versions <= V2.3.0 and Function State (FS) <= 3), SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0) (All versions <= V2.2.2 and Function State (FS) <= 8), SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA1) (All versions <= V2.3.0 and Function State (FS) <= 3), SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0) (All versions <= V2.2.2 and Function State (FS) <= 10), SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA1) (All versions <= V2.3.0 and Function State (FS) <= 3), SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 11), SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 10), SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 10), SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 12), SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 9), SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 9), SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 8), SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0) (All versions <= V2.5.0 and Function State (FS) <= 8), SIMATIC S7-200 SMART CPU family (All versions). There is an access mode used during manufacturing of the affected devices that allows additional diagnostic functionality. The security vulnerability could be exploited by an attacker with physical access to the UART interface during boot process.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
暴露危险的方法或函数
Source: CVE Program / CVE List V5
Vulnerability Title
Siemens SIMATIC S7-200和S7-1200 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens SIMATIC S7-200 Smart和Siemens SIMATIC S7-1200都是德国西门子(Siemens)公司的产品。Siemens SIMATIC S7-200 Smart是一款应用于中小型自动化系统中的可编程逻辑控制器(PLC)。Siemens SIMATIC S7-1200是一款S7-1200系列PLC(可编程逻辑控制器)。 Siemens S7-1200和SIMATIC S7-200中存在输入验证错误漏洞。攻击者可利用该漏洞访问其他诊断功能绕过安全限制,影响系统的完整
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Siemens AG SIMATIC S7-1200 CPU family (incl. SIPLUS variants) All versions -
Siemens AG SIMATIC S7-1200 CPU family < V4.x (incl. SIPLUS variants) All versions -
Siemens AG SIMATIC S7-1200 CPU family V4.x (incl. SIPLUS variants) All versions with Function State (FS) < 11 -
Siemens AG SIMATIC S7-200 SMART CPU CR20s (6ES7 288-1CR20-0AA1) All versions <= V2.3.0 and Function State (FS) <= 3 -
Siemens AG SIMATIC S7-200 SMART CPU CR30s (6ES7 288-1CR30-0AA1) All versions <= V2.3.0 and Function State (FS) <= 3 -
Siemens AG SIMATIC S7-200 SMART CPU CR40 (6ES7 288-1CR40-0AA0) All versions <= V2.2.2 and Function State (FS) <= 8 -
Siemens AG SIMATIC S7-200 SMART CPU CR40s (6ES7 288-1CR40-0AA1) All versions <= V2.3.0 and Function State (FS) <= 3 -
Siemens AG SIMATIC S7-200 SMART CPU CR60 (6ES7 288-1CR60-0AA0) All versions <= V2.2.2 and Function State (FS) <= 10 -
Siemens AG SIMATIC S7-200 SMART CPU CR60s (6ES7 288-1CR60-0AA1) All versions <= V2.3.0 and Function State (FS) <= 3 -
Siemens AG SIMATIC S7-200 SMART CPU SR20 (6ES7 288-1SR20-0AA0) All versions <= V2.5.0 and Function State (FS) <= 11 -
Siemens AG SIMATIC S7-200 SMART CPU SR30 (6ES7 288-1SR30-0AA0) All versions <= V2.5.0 and Function State (FS) <= 10 -
Siemens AG SIMATIC S7-200 SMART CPU SR40 (6ES7 288-1SR40-0AA0) All versions <= V2.5.0 and Function State (FS) <= 10 -
Siemens AG SIMATIC S7-200 SMART CPU SR60 (6ES7 288-1SR60-0AA0) All versions <= V2.5.0 and Function State (FS) <= 12 -
Siemens AG SIMATIC S7-200 SMART CPU ST20 (6ES7 288-1ST20-0AA0) All versions <= V2.5.0 and Function State (FS) <= 9 -
Siemens AG SIMATIC S7-200 SMART CPU ST30 (6ES7 288-1ST30-0AA0) All versions <= V2.5.0 and Function State (FS) <= 9 -
Siemens AG SIMATIC S7-200 SMART CPU ST40 (6ES7 288-1ST40-0AA0) All versions <= V2.5.0 and Function State (FS) <= 8 -
Siemens AG SIMATIC S7-200 SMART CPU ST60 (6ES7 288-1ST60-0AA0) All versions <= V2.5.0 and Function State (FS) <= 8 -
Siemens AG SIMATIC S7-200 SMART CPU family All versions -

II. Public POCs for CVE-2019-13945

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-13945

登录查看更多情报信息。

Vendor Advisories for CVE-2019-13945 (1)

Same Patch Batch · Siemens AG · 2019-12-12 · 8 CVEs total

CVE-2019-13927 Siemens Desigo PX 安全漏洞
CVE-2019-13930 Siemens XHQ Operations Intelligence 跨站请求伪造漏洞
CVE-2019-13931 Siemens XHQ Operations Intelligence 跨站脚本漏洞
CVE-2019-13932 Siemens XHQ Operations Intelligence 安全漏洞
CVE-2019-13942 Siemens EN100 Ethernet Module 缓冲区错误漏洞
CVE-2019-13943 Siemens EN100 Ethernet Module 跨站脚本漏洞
CVE-2019-13944 Siemens EN100 Ethernet module 路径遍历漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2019-13945

No comments yet


Leave a comment