Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-6569

Quick assessment

Affected
Siemens SCALANCE X204-2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Siemens Scalance X-200是德国西门子(Siemens)公司的一款工业级以太网交换机。 多款Siemen产品中存在安全漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。以下产品及版本受到影响:Siemen Scalance X-200 V5.2.4之前版本;Scalance X-300(全部版本);Scalance XP-200 4.1之前版本;Scalance XC-200 4.1之前版本;Scalance XF-200 4.1之前版本。

AI Predicted 5.5 Difficulty: Moderate EPSS 1.33% · P70
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-6569

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
预期行为违背
Source: CVE Program / CVE List V5
Vulnerability Title
多款Siemens产品安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens Scalance X-200是德国西门子(Siemens)公司的一款工业级以太网交换机。 多款Siemen产品中存在安全漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。以下产品及版本受到影响:Siemen Scalance X-200 V5.2.4之前版本;Scalance X-300(全部版本);Scalance XP-200 4.1之前版本;Scalance XC-200 4.1之前版本;Scalance XF-200 4.1之前版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Siemens SCALANCE X204-2 All versions < V5.2.6 -
Siemens SCALANCE X204-2FM All versions < V5.2.6 -
Siemens SCALANCE X204-2LD All versions < V5.2.6 -
Siemens SCALANCE X204-2LD TS All versions < V5.2.6 -
Siemens SCALANCE X204-2TS All versions < V5.2.6 -
Siemens SCALANCE X206-1 All versions < V5.2.6 -
Siemens SCALANCE X206-1LD All versions < V5.2.6 -
Siemens SCALANCE X208 All versions < V5.2.6 -
Siemens SCALANCE X208PRO All versions < V5.2.6 -
Siemens SCALANCE X212-2 All versions < V5.2.6 -
Siemens SCALANCE X212-2LD All versions < V5.2.6 -
Siemens SCALANCE X216 All versions < V5.2.6 -
Siemens SCALANCE X224 All versions < V5.2.6 -
Siemens SCALANCE X302-7 EEC (230V) All versions < V4.1.3 -
Siemens SCALANCE X302-7 EEC (230V, coated) All versions < V4.1.3 -
Siemens SCALANCE X302-7 EEC (24V) All versions < V4.1.3 -
Siemens SCALANCE X302-7 EEC (24V, coated) All versions < V4.1.3 -
Siemens SCALANCE X302-7 EEC (2x 230V) All versions < V4.1.3 -
Siemens SCALANCE X302-7 EEC (2x 230V, coated) All versions < V4.1.3 -
Siemens SCALANCE X302-7 EEC (2x 24V) All versions < V4.1.3 -
Siemens SCALANCE X302-7 EEC (2x 24V, coated) All versions < V4.1.3 -
Siemens SCALANCE X304-2FE All versions < V4.1.3 -
Siemens SCALANCE X306-1LD FE All versions < V4.1.3 -
Siemens SCALANCE X307-2 EEC (230V) All versions < V4.1.3 -
Siemens SCALANCE X307-2 EEC (230V, coated) All versions < V4.1.3 -
Siemens SCALANCE X307-2 EEC (24V) All versions < V4.1.3 -
Siemens SCALANCE X307-2 EEC (24V, coated) All versions < V4.1.3 -
Siemens SCALANCE X307-2 EEC (2x 230V) All versions < V4.1.3 -
Siemens SCALANCE X307-2 EEC (2x 230V, coated) All versions < V4.1.3 -
Siemens SCALANCE X307-2 EEC (2x 24V) All versions < V4.1.3 -

II. Public POCs for CVE-2019-6569

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-6569

请登录查看更多情报信息。

Vendor Advisories for CVE-2019-6569 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2019-6569

No comments yet


Leave a comment