CVE-2019-10938
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1), Siemens Power Meters Series 9810 (All versions). An unauthenticated attacker with network access to the device could potentially insert arbitrary code which is executed before firmware verification in the device. At the time of advisory publication no public exploitation of this security vulnerability was known.
Published:Aug 2, 2019
Last Modified:Nov 21, 2024
EPS:Aug 2, 2019
EPSS Score:0.00487
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Siemens
Product
6md85
Siemens
6md85
Vendor
Siemens
Product
6md86
Siemens
6md86
Vendor
Siemens
Product
6md89
Siemens
6md89
Vendor
Siemens
Product
7sa82
Siemens
7sa82
Vendor
Siemens
Product
7sa86
Siemens
7sa86
Vendor
Siemens
Product
7sa87
Siemens
7sa87
Vendor
Siemens
Product
7sd82
Siemens
7sd82
Vendor
Siemens
Product
7sd86
Siemens
7sd86
Vendor
Siemens
Product
7sd87
Siemens
7sd87
Vendor
Siemens
Product
7sj82
Siemens
7sj82
Vendor
Siemens
Product
7sj85
Siemens
7sj85
Vendor
Siemens
Product
7sj86
Siemens
7sj86
Vendor
Siemens
Product
7sk82
Siemens
7sk82
Vendor
Siemens
Product
7sk85
Siemens
7sk85
Vendor
Siemens
Product
7sl82
Siemens
7sl82
Vendor
Siemens
Product
7sl86
Siemens
7sl86
Vendor
Siemens
Product
7sl87
Siemens
7sl87
Vendor
Siemens
Product
7um85
Siemens
7um85
Vendor
Siemens
Product
7ut82
Siemens
7ut82
Vendor
Siemens
Product
7ut85
Siemens
7ut85
Vendor
Siemens
Product
7ut86
Siemens
7ut86
Vendor
Siemens
Product
7ut87
Siemens
7ut87
Vendor
Siemens
Product
7ve85
Siemens
7ve85
Vendor
Siemens
Product
7vk87
Siemens
7vk87
Vendor
Siemens
Product
Siprotec 5 Digsi Device Driver
Siemens
Siprotec 5 Digsi Device Driver
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
