Rewterz
Rewterz Threat Advisory – CVE-2019-10922 – Siemens SIMATIC WinCC and SIMATIC PCS 7 Remote Code Execution Vulnerability
May 15, 2019
Rewterz
Rewterz Threat Advisory – ZombieLoad Chip Flaws in Apple, Amazon, Google, Microsoft and Mozilla Products That Use Intel CPUs
May 15, 2019

Rewterz Threat Advisory – CVE-2019-6574 – Siemens SINAMICS PERFECT HARMONY GH180 Fieldbus Network Denial of Service Vulnerability

Severity

Medium

Analysis Summary

An improperly configured parameter read/write execution via fieldbus network may cause the controller to restart. An attacker with access to the fieldbus network could cause a denial-of-service condition by sending specially crafted packets.
The vulnerability could be exploited by an attacker with network access to the device. Successful exploitation requires no privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the affected system.

Impact

Denial of service

Affected Vendors

Siemens

Affected Products

SINAMICS PERFECT HARMONY GH180 Fieldbus Network

Remediation

Vendor recommends users upgrade to NXGpro control.

Vendor has identified the following specific workarounds and mitigation that users can apply to reduce the risk:

  • Disable the fieldbus parameter read/write functionality
  • Apply cell protection concept and implement defense in depth