Rewterz
Rewterz Threat Advisory – GE Mark VIe Controller Multiple Vulnerabilities
October 9, 2019
Rewterz
Rewterz Threat Advisory – CVE-2019-13929 – Siemens SIMATIC IT UADM Vulnerability
October 9, 2019

Rewterz Threat Advisory – CVE-2019-13921 – Siemens SIMATIC WinAC RTX (F) 2010 Denial of Service Vulnerability

Severity

Medium

Analysis Summary

An unauthenticated attacker sending a large HTTP request to the host where WinAC RTX is running may trigger a denial-of-service condition.

Impact

Denial of service

Affected Vendors

Siemens

Affected Products

SIMATIC WinAC RTX (F) 2010 all versions

Remediation

Siemens has identified the following specific workarounds and mitigation’s users can apply to reduce the risk:

  • Restrict network access to the host containing the affected service.
  • If the service is not used as a server, configure Windows Firewall to disable communications on the port of the vulnerable service.