HIGH🇵🇱 Wersja polska

CVE-2019-10953

CVSS 7.5v3.1pub. 2019-04-17upd. 2026-06-04

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Abb Pm554 Tp Eth

    HW
    Abb
    all versions
  • Abb Pm554 Tp Eth Firmware

    OS
    Abb
    all versions
  • Phoenixcontact Ilc 151 Eth

    HW
    Phoenixcontact
    all versions
  • Phoenixcontact Ilc 151 Eth Firmware

    OS
    Phoenixcontact
    all versions
  • Schneider Electric Modicon M221

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Modicon M221 Firmware

    OS
    Schneider-Electric
    < 1.10.0.0
  • Siemens 6ed1052 1cc01 0ba8

    HW
    Siemens
    all versions
  • Siemens 6ed1052 1cc01 0ba8 Firmware

    OS
    Siemens
    all versions
  • Siemens 6es7211 1ae40 0xb0

    HW
    Siemens
    all versions
  • Siemens 6es7211 1ae40 0xb0 Firmware

    OS
    Siemens
    all versions
  • Siemens 6es7314 6eh04 0ab0

    HW
    Siemens
    all versions
  • Siemens 6es7314 6eh04 0ab0 Firmware

    OS
    Siemens
    all versions
  • Wago Bacnet\/ip

    HW
    Wago
    all versions
  • Wago Bacnet\/ip Firmware

    OS
    Wago
    all versions
  • Wago Ethernet

    HW
    Wago
    all versions
  • Wago Ethernet Firmware

    OS
    Wago
    all versions
  • Wago Knx Ip

    HW
    Wago
    all versions
  • Wago Knx Ip Firmware

    OS
    Wago
    all versions
  • Wago Pfc100

    HW
    Wago
    all versions
  • Wago Pfc100 Firmware

    OS
    Wago
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-1698CRITICAL9.8PL ✓same product

WAGO: Zdalne przejęcie kontroli przez nieuprawnionego atakującego (command injection)

CVE-2022-45138CRITICAL9.8PL ✓same product

WAGO 751-9301/752-8303: Pominięcie uwierzytelnienia w API zarządzania

CVE-2022-45140CRITICAL9.8PL ✓same product

WAGO 751/752: Nieuwierzytelniony zapis danych z uprawnieniami root – RCE

CVE-2020-7489CRITICAL9.8PL ✓same product

Podatność Injection w oprogramowaniu Schneider Electric – podstawianie DLL

CVE-2020-8597CRITICAL9.8PL ✓same product

Buffer overflow w pppd (ppp 2.4.2–2.4.8) — podatność w obsłudze EAP