Publication Date: 2019-12-10
Last Update: 2020-01-14
Current Version: V1.1
CVSS v3.1 Base Score: 7.5

Affected Product and Versions Remediation
EN100 Ethernet module IEC 61850 variant:
All versions < V4.37
Update to V4.37
https://support.industry.siemens.com/cs/us/en/view/109745821
EN100 Ethernet module PROFINET IO variant:
All versions
See recommendations from Section Workaround and Mitigations
EN100 Ethernet module Modbus TCP variant:
All versions
See recommendations from Section Workaround and Mitigations
EN100 Ethernet module DNP3 variant:
All versions
See recommendations from Section Workaround and Mitigations
EN100 Ethernet module IEC104 variant:
All versions
See recommendations from Section Workaround and Mitigations

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS v3.1 Base Score 7.2
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L/E:P/RL:O/RC:C
CWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-23: Relative Path Traversal

https://www.siemens.com/cert/advisories