CVE-2019-10927
A vulnerability has been identified in SCALANCE SC-600 (V2.0), SCALANCE XB-200 (V4.1), SCALANCE XC-200 (V4.1), SCALANCE XF-200BA (V4.1), SCALANCE XP-200 (V4.1), SCALANCE XR-300WG (V4.1). An authenticated attacker with network access to to port 22/tcp of an affected device may cause a Denial-of-Service condition. The security vulnerability could be exploited by an authenticated attacker with network access to the affected device. No user interaction is required to exploit this vulnerability. The vulnerability impacts the availability of the affected device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.17%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (5)
CWE
- CWE-703
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-10927",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "productcert@siemens.com",
"affectedData": [
{
"vendor": "Siemens AG",
"product": "SCALANCE SC-600",
"versions": [
{
"status": "affected",
"version": "V2.0"
}
]
},
{
"vendor": "Siemens AG",
"product": "SCALANCE XB-200",
"versions": [
{
"status": "affected",
"version": "V4.1"
}
]
},
{
"vendor": "Siemens AG",
"product": "SCALANCE XC-200",
"versions": [
{
"status": "affected",
"version": "V4.1"
}
]
},
{
"vendor": "Siemens AG",
"product": "SCALANCE XF-200BA",
"versions": [
{
"status": "affected",
"version": "V4.1"
}
]
},
{
"vendor": "Siemens AG",
"product": "SCALANCE XP-200",
"versions": [
{
"status": "affected",
"version": "V4.1"
}
]
},
{
"vendor": "Siemens AG",
"product": "SCALANCE XR-300WG",
"versions": [
{
"status": "affected",
"version": "V4.1"
}
]
}
]
}
],
"published": "2019-08-13T19:15:14.687",
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-671286.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "productcert@siemens.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-671286.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productcert@siemens.com",
"description": [
{
"lang": "en",
"value": "CWE-703"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in SCALANCE SC-600 (V2.0), SCALANCE XB-200 (V4.1), SCALANCE XC-200 (V4.1), SCALANCE XF-200BA (V4.1), SCALANCE XP-200 (V4.1), SCALANCE XR-300WG (V4.1). An authenticated attacker with network access to to port 22/tcp of an affected device may cause a Denial-of-Service condition. The security vulnerability could be exploited by an authenticated attacker with network access to the affected device. No user interaction is required to exploit this vulnerability. The vulnerability impacts the availability of the affected device."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad en SCALANCE SC-600 (V2.0), SCALANCE XB-200 (V4.1), SCALANCE XC-200 (V4.1), SCALANCE XF-200BA (V4.1), SCALANCE XP-200 (V4.1), SCALANCE XR-300WG (V4.1). Un atacante autenticado con acceso de red al puerto 22 / tcp de un dispositivo afectado puede causar una condición de denegación de servicio. La vulnerabilidad de seguridad podría ser explotada por un atacante autenticado con acceso de red al dispositivo afectado. No se requiere interacción del usuario para explotar esta vulnerabilidad. La vulnerabilidad afecta la disponibilidad del dispositivo afectado."
}
],
"lastModified": "2026-06-17T02:11:55.527",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:scalance_xb-200_firmware:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59FC4C43-451E-48F9-BCDF-F6C8CC8EA123"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6CB3CC2D-CBF0-4F53-A412-01BBC39E34C2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:scalance_xc-200_firmware:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8369D3C-1C5C-4734-9D97-2F90FDC13DF1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7719E194-EE3D-4CE8-8C85-CF0D82A553AA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:scalance_xf-200ba_firmware:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9AE14B3E-51F1-4A5A-979F-50A08DEA9E50"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:scalance_xf-200ba:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "58377C58-F660-4C17-A3CB-BFC2F28848CD"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:scalance_xp-200_firmware:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51357BC6-D9A7-4A3F-AB27-5B0CDEDAF635"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8F962FC7-0616-467F-8CCA-ADEA224B5F7B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:scalance_xr-300wg_firmware:4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9011641-C6CD-42D7-A3E4-6FF9F6CB50DF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:scalance_xr-300wg:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "434BC9BE-C5DB-4DAF-8E07-DFE4EEA0D7FE"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "productcert@siemens.com"
}