We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2019-18299



Description

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, CVE-2019-18306, and CVE-2019-18307. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

Reserved 2019-10-23 | Published 2019-12-12 | Updated 2024-08-05 | Assigner siemens

Problem types

CWE-190: Integer Overflow or Wraparound

Product status

All versions
affected

References

cert-portal.siemens.com/productcert/pdf/ssa-451445.pdf

packetstormsecurity.com/...ry-SPPA-T3000-Code-Execution.html

cve.org (CVE-2019-18299)

nvd.nist.gov (CVE-2019-18299)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2019-18299

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.