U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-6568

Change History

Modified Analysis by NIST 9/28/2020 8:32:48 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:sinamics_gh150_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 4.8
          *cpe:2.3:o:siemens:sinamics_gh150_firmware:4.8:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_gh150:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:sinamics_gl150_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 4.8
          *cpe:2.3:o:siemens:sinamics_gl150_firmware:4.8:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_gl150:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:sinamics_gm150_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 4.8
          *cpe:2.3:o:siemens:sinamics_gm150_firmware:4.8:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_gm150:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:sinamics_sl150_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 4.8
          *cpe:2.3:o:siemens:sinamics_sl150_firmware:4.8:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_sl150:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:sinamics_sm120_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 4.8
          *cpe:2.3:o:siemens:sinamics_sm120_firmware:4.8:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_sm120:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:sinamics_sm150_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1
          *cpe:2.3:o:siemens:sinamics_sm150_firmware:5.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_sm150:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_et_200_sp_open_controller_cpu_1515sp_pc2_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_et_200_sp_open_controller_cpu_1515sp_pc2:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_et_200_sp_open_controller_cpu_1515sp_pc2_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.7
     OR
          cpe:2.3:h:siemens:simatic_et_200_sp_open_controller_cpu_1515sp_pc2:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_outdoor_panels:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
          *cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_firmware:15.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_outdoor_panels:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_panels_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_panels:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_panels_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
          *cpe:2.3:o:siemens:simatic_hmi_comfort_panels_firmware:15.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_panels:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp400f_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp400f:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp400f_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp400f_firmware:15.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp400f:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp700:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700_firmware:15.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp700:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700f_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp700f:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700f_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700f_firmware:15.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp700f:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp900:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900_firmware:15.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp900:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900f_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp900f:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900f_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900f_firmware:15.1:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp900f:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf185c_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_rf185c:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf185c_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 1.1.0
     OR
          cpe:2.3:h:siemens:simatic_rf185c:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf186c_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_rf186c:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf186c_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 1.1.0
     OR
          cpe:2.3:h:siemens:simatic_rf186c:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf188c_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_rf188c:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf188c_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 1.1.0
     OR
          cpe:2.3:h:siemens:simatic_rf188c:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf600r_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_rf600r:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_rf600r_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 3.2.1
     OR
          cpe:2.3:h:siemens:simatic_rf600r:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.1
     OR
          cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500f_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_s7-1500f:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500f_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.1
     OR
          cpe:2.3:h:siemens:simatic_s7-1500f:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500s_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_s7-1500s:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500s_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.1
     OR
          cpe:2.3:h:siemens:simatic_s7-1500s:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500t_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-1500t_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.1
     OR
          cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-300_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_s7-300:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_s7-300_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 3.3.17
     OR
          cpe:2.3:h:siemens:simatic_s7-300:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simatic_winac_rtx_2010_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_winac_rtx_2010:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simatic_winac_rtx_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2010
          *cpe:2.3:o:siemens:simatic_winac_rtx_firmware:2010:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_winac_rtx:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simocode_pro_v_eip_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simocode_pro_v_eip:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simocode_pro_v_eip_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 1.1.3
     OR
          cpe:2.3:h:siemens:simocode_pro_v_eip:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:simocode_pro_v_pn_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simocode_pro_v_pn:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:simocode_pro_v_pn_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.1.3
     OR
          cpe:2.3:h:siemens:simocode_pro_v_pn:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:sinamics_s150_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1
          *cpe:2.3:o:siemens:sinamics_s150_firmware:5.1:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:sinamics_s150_firmware:5.1:sp1:*:*:*:*:*:*
          *cpe:2.3:o:siemens:sinamics_s150_firmware:5.1:sp1_hf2:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_s150:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:sinamics_s150_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 5.1
          *cpe:2.3:o:siemens:sinamics_s150_firmware:5.1:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:sinamics_s150_firmware:5.1:sp1:*:*:*:*:*:*
          *cpe:2.3:o:siemens:sinamics_s150_firmware:5.1:sp1_hotfix2:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sinamics_s150:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:sitop_psu8600_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sitop_psu8600:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:sitop_psu8600_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 1.5
     OR
          cpe:2.3:h:siemens:sitop_psu8600:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:sitop_ups1600_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:sitop_ups1600:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:sitop_ups1600_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.3
     OR
          cpe:2.3:h:siemens:sitop_ups1600:-:*:*:*:*:*:*:*
Changed CPE Configuration
AND
     OR
          *cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:tim_1531_irc:-:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.1
     OR
          cpe:2.3:h:siemens:tim_1531_irc:-:*:*:*:*:*:*:*
Changed CPE Configuration
OR
     *cpe:2.3:a:siemens:simatic_cp443-1_opc_ua:*:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_ipc_diagmonitor:*:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_s7-1500_software_controller:*:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_s7-plcsim_advanced:*:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:*:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:sitop_manager:*:*:*:*:*:*:*:*
OR
     *cpe:2.3:a:siemens:simatic_cp443-1_opc_ua:*:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_ipc_diagmonitor:*:*:*:*:*:*:*:* versions up to (excluding) 5.1.3
     *cpe:2.3:a:siemens:simatic_s7-1500_software_controller:*:*:*:*:*:*:*:* versions up to (excluding) 2.7
     *cpe:2.3:a:siemens:simatic_s7-plcsim_advanced:*:*:*:*:*:*:*:* versions up to (excluding) 2.0
     *cpe:2.3:a:siemens:simatic_s7-plcsim_advanced:2.0:-:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_s7-plcsim_advanced:2.0:sp1:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:*:*:*:*:*:*:*:* versions up to (excluding) 15.1
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:15.1:-:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:15.1:update1:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:15.1:update2:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:15.1:update3:*:*:*:*:*:*
     *cpe:2.3:a:siemens:sitop_manager:*:*:*:*:*:*:*:* versions up to (excluding) 1.1
Removed CVSS V3
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

								
						
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Added CWE

								
							
							
						
NIST CWE-125
Removed CWE
NIST CWE-20

								
						
Changed Reference Type
https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdf No Types Assigned
https://cert-portal.siemens.com/productcert/pdf/ssa-530931.pdf Vendor Advisory