U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-10926

Change History

CVE Modified by Siemens AG 3/15/2021 2:15:15 PM

Action Type Old Value New Value
Changed Description
A vulnerability has been identified in SIMATIC MV400 family (All Versions <  V7.0.6). Communication with the device is not encrypted. Data transmitted between the
device and the user can be obtained by an attacker in a privileged network
position.

The security vulnerability can be exploited by an attacker in a privileged
network position which allows eavesdropping the communication between the
affected device and the user. The user must invoke a session. Successful
exploitation of the vulnerability compromises confidentiality of the data
transmitted.
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted between the device and the user can be obtained by an attacker in a privileged network position. The security vulnerability can be exploited by an attacker in a privileged network position which allows eavesdropping the communication between the affected device and the user. The user must invoke a session. Successful exploitation of the vulnerability compromises confidentiality of the data transmitted.