CVE-2019-19279
Estado: ModificadaAlta (7.5)—
A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Specially crafted packets sent to port 50000/UDP of the EN100 Ethernet communication modules could cause a Denial-of-Service of the affected device. A manual reboot is required to recover the service of the device. At the time of advisory publication no public exploitation of this security vulnerability was known to Siemens.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.59%
- Percentil entre todas las CVEs puntuadas: 75
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-19279",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "productcert@siemens.com",
"affectedData": [
{
"vendor": "Siemens AG",
"product": "SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules",
"versions": [
{
"status": "affected",
"version": "All versions"
}
]
}
]
}
],
"published": "2020-03-10T20:15:18.807",
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-974843.pdf",
"tags": [
"Vendor Advisory"
],
"source": "productcert@siemens.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-974843.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productcert@siemens.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Specially crafted packets sent to port 50000/UDP of the EN100 Ethernet communication modules could cause a Denial-of-Service of the affected device. A manual reboot is required to recover the service of the device. At the time of advisory publication no public exploitation of this security vulnerability was known to Siemens."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad en los relés SIPROTEC 4 y SIPROTEC Compact equipados con módulos de comunicación EN100 Ethernet (todas las versiones). Paquetes especialmente diseñados enviados hacia el puerto 50000/UDP de los módulos de comunicación Ethernet EN100 podrían causar una Denegación de Servicio del dispositivo afectado. Es requerido un reinicio manual para recuperar el servicio del dispositivo. Al momento de la publicación del aviso, no se conocía por Siemens una explotación pública de esta vulnerabilidad de seguridad."
}
],
"lastModified": "2026-06-17T02:26:25.390",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:siemens:siprotec_4:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50A4AC48-7BF4-40F9-9D86-328F94A85683"
},
{
"criteria": "cpe:2.3:a:siemens:siprotec_compact:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6CB31CA-11BC-4185-8BCF-964E30EFE10F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "productcert@siemens.com"
}