← Vulnerability feed

Vulnerability record · CVE-2019-10942 · published 13 August 2019

CVE-2019-10942: Siemens scalance x-200 firmware uncontrolled resource consumption vulnerability

Siemens · Scalance X 200 Firmware

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X204RNA (HSR) (All versions), SCALANCE X204RNA (PRP) (All versions), SCALANCE X204RNA EEC (HSR) (All versions), SCALANCE X204RNA EEC (PRP) (All versions), SCALANCE X204RNA EEC (PRP/HSR) (All versions). The device contains a vulnerability that could allow an attacker to trigger a denial-of-service condition by sending large message packages repeatedly to the telnet service. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.

8.6 CVSS 3.1 High EPSS 1.4% · top 29.4% CWE-400 · Uncontrolled resource consumption
8.6CVSS 3.1 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X204RNA (HSR) (All versions), SCALANCE X204RNA (PRP) (All versions), SCALANCE X204RNA EEC (HSR) (All versions), SCALANCE X204RNA EEC (PRP) (All versions), SCALANCE X204RNA EEC (PRP/HSR) (All versions). The device contains a vulnerability that could allow an attacker to trigger a denial-of-service condition by sending large message packages repeatedly to the telnet service. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10942 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-6569Siemens scalance x-200 firmware vulnerabilityThe monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attac…EPSS 1.3%8.6CVE-2019-13933Siemens scalance x-200rna firmware missing authentication for critical function vulnerabilityA vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALAN…EPSS 1.4%7.5CVE-2019-19301Siemens scalance xc-200 firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT…EPSS 1.4%7.5CVE-2019-13946Siemens dk standard ethernet controller uncontrolled resource consumption vulnerabilityProfinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package request…EPSS 1.5%7.5CVE-2019-10923Siemens cp1604 firmware uncontrolled resource consumption vulnerabilityAn attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the…EPSS 1.4%6.1CVE-2018-4848Siemens scalance x300 firmware cross-site scripting vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch fam…EPSS 1.0%5.5CVE-2019-6567Siemens scalance x-200 firmware insufficiently protected credentials vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch fam…EPSS 0.30%5.4CVE-2019-13924Siemens scalance xc-200 firmware clickjacking vulnerabilityA vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1),…EPSS 0.83%

Source: NIST National Vulnerability Database (record CVE-2019-10942), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.