CVE-2019-6569
Siemens · published 2019-03-26
Source record Collected from the National Vulnerability Database (NVD)
Description
Description by Siemens AG via the CVE Program.
The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.
Status at the source
- NVD status: Modified
Affected products, as the source lists them
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SCALANCE X204-2 | All versions < V5.2.6: affected |
| Siemens | SCALANCE X204-2FM | All versions < V5.2.6: affected |
| Siemens | SCALANCE X204-2LD | All versions < V5.2.6: affected |
| Siemens | SCALANCE X204-2LD TS | All versions < V5.2.6: affected |
| Siemens | SCALANCE X204-2TS | All versions < V5.2.6: affected |
| Siemens | SCALANCE X206-1 | All versions < V5.2.6: affected |
| Siemens | SCALANCE X206-1LD | All versions < V5.2.6: affected |
| Siemens | SCALANCE X208 | All versions < V5.2.6: affected |
| Siemens | SCALANCE X208PRO | All versions < V5.2.6: affected |
| Siemens | SCALANCE X212-2 | All versions < V5.2.6: affected |
| Siemens | SCALANCE X212-2LD | All versions < V5.2.6: affected |
| Siemens | SCALANCE X216 | All versions < V5.2.6: affected |
| Siemens | SCALANCE X224 | All versions < V5.2.6: affected |
| Siemens | SCALANCE X302-7 EEC (230V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X302-7 EEC (230V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X302-7 EEC (24V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X302-7 EEC (24V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X302-7 EEC (2x 230V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X302-7 EEC (2x 230V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X302-7 EEC (2x 24V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X302-7 EEC (2x 24V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X304-2FE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X306-1LD FE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (230V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (230V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (24V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (24V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (2x 230V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (2x 230V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (2x 24V) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-2 EEC (2x 24V, coated) | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-3 | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-3 | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-3LD | All versions < V4.1.3: affected |
| Siemens | SCALANCE X307-3LD | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2 | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2 | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2LD | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2LD | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2LH | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2LH | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2LH+ | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2LH+ | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2M | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2M | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2M PoE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2M PoE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2M TS | All versions < V4.1.3: affected |
| Siemens | SCALANCE X308-2M TS | All versions < V4.1.3: affected |
| Siemens | SCALANCE X310 | All versions < V4.1.3: affected |
| Siemens | SCALANCE X310 | All versions < V4.1.3: affected |
| Siemens | SCALANCE X310FE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X310FE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X320-1 FE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X320-1-2LD FE | All versions < V4.1.3: affected |
| Siemens | SCALANCE X408-2 | All versions < V4.1.3: affected |
| Siemens | SCALANCE XB205-3 (SC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB205-3 (SC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB205-3 (ST/BFOC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB205-3 (ST/BFOC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB205-3LD | All versions < V4.1: affected |
| Siemens | SCALANCE XB205-3LD | All versions < V4.1: affected |
| Siemens | SCALANCE XB208 | All versions < V4.1: affected |
| Siemens | SCALANCE XB208 | All versions < V4.1: affected |
| Siemens | SCALANCE XB213-3 (SC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB213-3 (SC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB213-3 (ST/BFOC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB213-3 (ST/BFOC) | All versions < V4.1: affected |
| Siemens | SCALANCE XB213-3LD | All versions < V4.1: affected |
| Siemens | SCALANCE XB213-3LD | All versions < V4.1: affected |
| Siemens | SCALANCE XB216 | All versions < V4.1: affected |
| Siemens | SCALANCE XB216 | All versions < V4.1: affected |
| Siemens | SCALANCE XC206-2 (SC) | All versions < V4.1: affected |
| Siemens | SCALANCE XC206-2 (ST/BFOC) | All versions < V4.1: affected |
| Siemens | SCALANCE XC206-2SFP | All versions < V4.1: affected |
| Siemens | SCALANCE XC206-2SFP EEC | All versions < V4.1: affected |
| Siemens | SCALANCE XC206-2SFP G | All versions < V4.1: affected |
| Siemens | SCALANCE XC206-2SFP G | All versions < V4.1: affected |
| Siemens | SCALANCE XC206-2SFP G EEC | All versions < V4.1: affected |
| Siemens | SCALANCE XC208 | All versions < V4.1: affected |
| Siemens | SCALANCE XC208EEC | All versions < V4.1: affected |
| Siemens | SCALANCE XC208G | All versions < V4.1: affected |
| Siemens | SCALANCE XC208G | All versions < V4.1: affected |
| Siemens | SCALANCE XC208G EEC | All versions < V4.1: affected |
| Siemens | SCALANCE XC216 | All versions < V4.1: affected |
| Siemens | SCALANCE XC216-4C | All versions < V4.1: affected |
| Siemens | SCALANCE XC216-4C G | All versions < V4.1: affected |
| Siemens | SCALANCE XC216-4C G (EIP Def.) | All versions < V4.1: affected |
| Siemens | SCALANCE XC216-4C G EEC | All versions < V4.1: affected |
| Siemens | SCALANCE XC216EEC | All versions < V4.1: affected |
| Siemens | SCALANCE XC224 | All versions < V4.1: affected |
| Siemens | SCALANCE XC224-4C G | All versions < V4.1: affected |
| Siemens | SCALANCE XC224-4C G (EIP Def.) | All versions < V4.1: affected |
| Siemens | SCALANCE XC224-4C G EEC | All versions < V4.1: affected |
| Siemens | SCALANCE XF204 | All versions < V5.2.6: affected |
| Siemens | SCALANCE XF204 | All versions < V4.1: affected |
| Siemens | SCALANCE XF204 DNA | All versions < V4.1: affected |
| Siemens | SCALANCE XF204-2 | All versions < V5.2.6: affected |
| Siemens | SCALANCE XF204-2BA | All versions < V4.1: affected |
| Siemens | SCALANCE XF204-2BA DNA | All versions < V4.1: affected |
The source lists more products than DeSpy shows; see the source record.
Products named in NVD's CPE match criteria (5)
cpe:2.3:o:siemens:scalance_x-200_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:siemens:scalance_x-300_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:siemens:scalance_xf-200_firmware:*:*:*:*:*:*:*:*
DeSpy has not checked any unit, hardware revision or firmware. A product missing here is not a statement that it is unaffected.
Scores, as their sources published them
- CVSS 3.1: 9.1 CRITICAL — as published by NIST (Primary)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H - CVSS 2.0: 6.4 MEDIUM — as published by NIST (Primary)
AV:N/AC:L/Au:N/C:P/I:N/A:P
DeSpy does not score records. These are the sources' own values.
Weaknesses
CWE-440, NVD-CWE-Other
Sources
References the source lists
- https://cert-portal.siemens.com/productcert/pdf/ssa-557804.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-557804.pdf
Source dates: published 2019-03-26, last changed 2026-06-17. DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.