Rewterz Threat Advisory – GE Mark VIe Controller Multiple Vulnerabilities
October 9, 2019Rewterz Threat Advisory – CVE-2019-13929 – Siemens SIMATIC IT UADM Vulnerability
October 9, 2019Rewterz Threat Advisory – GE Mark VIe Controller Multiple Vulnerabilities
October 9, 2019Rewterz Threat Advisory – CVE-2019-13929 – Siemens SIMATIC IT UADM Vulnerability
October 9, 2019Severity
Medium
Analysis Summary
An unauthenticated attacker sending a large HTTP request to the host where WinAC RTX is running may trigger a denial-of-service condition.
Impact
Denial of service
Affected Vendors
Siemens
Affected Products
SIMATIC WinAC RTX (F) 2010 all versions
Remediation
Siemens has identified the following specific workarounds and mitigation’s users can apply to reduce the risk:
- Restrict network access to the host containing the affected service.
- If the service is not used as a server, configure Windows Firewall to disable communications on the port of the vulnerable service.