CVE-2019-10953 - CVE House
Back to Database
Status published Unknown CVE-2019-10953

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic...

Vulnerability Description

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10953

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Matthias Niedermaier (Hochschule Augsburg), Jan-Ole Malchow (Freie Universität Berlin), and Florian Fischer (Hochschule Augsburg) reported this vulnerability to CISA.
  • Mikael Vingaard found and reported to CISA additional devices containing this vulnerability.

Affected Vendor

Affected Software

1SAP120600R0071 PM554-TP-ETH, 2700974 ILC 151 ETH, ILC 191 ETH 2TX, Modicon M221, EcoStruxure Machine Expert – Basic, 6ES7211-1AE40-0XB0 Simatic S7-1211, 6ES7314-6EH04-0AB0 Simatic S7-314, 6ED1052-1CC01-0BA8 Logo! 8, 750-889 Controller KNX IP, 750-8100 Controller PFC100, 750-880 Controller ETH, 750-831 Controller BACnet/IP
Vulnerable Versions:
Multiple, 0, v1.10.0.0, v1.0

Timeline

Official Publish: April 17th, 2019
Last Modified: June 4th, 2026
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)