← Vulnerability feed

Vulnerability record · CVE-2019-6567 · published 12 June 2019

CVE-2019-6567: Siemens scalance x-200 firmware insufficiently protected credentials vulnerability

Siemens · Scalance X 200 Firmware

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X-414-3E (All versions). The affected devices store passwords in a recoverable format. An attacker may extract and recover device passwords from the device configuration. Successful exploitation requires access to a device configuration backup and impacts confidentiality of the stored passwords.

5.5 CVSS 3.1 Medium EPSS 0.30% · top 79.6% CWE-257 · CWE-257CWE-522 · Insufficiently protected credentials
5.5CVSS 3.1 base score, v2 2.1
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X-414-3E (All versions). The affected devices store passwords in a recoverable format. An attacker may extract and recover device passwords from the device configuration. Successful exploitation requires access to a device configuration backup and impacts confidentiality of the stored passwords.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-6567 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-6569Siemens scalance x-200 firmware vulnerabilityThe monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attac…EPSS 1.3%8.6CVE-2019-13933Siemens scalance x-200rna firmware missing authentication for critical function vulnerabilityA vulnerability has been identified in SCALANCE X204RNA (HSR), SCALANCE X204RNA (PRP), SCALANCE X204RNA EEC (HSR), SCALANCE X204RNA EEC (PRP), SCALAN…EPSS 1.4%8.6CVE-2019-10942Siemens scalance x-200 firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch fam…EPSS 1.4%7.8CVE-2012-1802Siemens scalance x414-3e firmware memory buffer overflow vulnerabilityBuffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC …EPSS 6.1%7.5CVE-2019-19301Siemens scalance xc-200 firmware uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT…EPSS 1.4%7.5CVE-2019-13946Siemens dk standard ethernet controller uncontrolled resource consumption vulnerabilityProfinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package request…EPSS 1.5%7.5CVE-2019-10923Siemens cp1604 firmware uncontrolled resource consumption vulnerabilityAn attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the…EPSS 1.4%6.1CVE-2018-4848Siemens scalance x300 firmware cross-site scripting vulnerabilityA vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch fam…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2019-6567), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.