← back
CVE-2019-10953highCWE-400

CVE-2019-10953

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 3.4%
exploitation probability
3.4%top 12% of all CVEs
observed exploitation
nono source reports it
In short

Programmable Logic Controllers (PLCs) from major manufacturers can be crashed by flooding them with network packets, causing them to stop working. This affects critical industrial systems and infrastructure that rely on these controllers to operate.

Technical detail

A remote, unauthenticated attacker can trigger a denial-of-service condition by sending a high volume of crafted network packets to vulnerable PLCs (ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO). The attack exploits insufficient input validation or resource exhaustion mechanisms, resulting in service unavailability of industrial control systems.

Summary generated and translated by AI from the official description.
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H