← back
CVE-2019-13927

CVE-2019-13927

EPSS 1.7%CWE-472
In short

A flaw in Desigo PX automation controllers allows attackers to crash the web server by sending a specially crafted HTTP message, making the web interface unavailable until the device is rebooted. The device itself continues to work, but users cannot access it remotely through the web interface.

Technical detail

The vulnerability is a denial of service affecting the web server component of Desigo PX controllers (firmware versions < V6.00.320). An unauthenticated attacker with network access to the HTTP port (tcp/80) can trigger a crash condition by sending a malformed HTTP request; successful exploitation results in the web server becoming unresponsive (returning HTTP 404 for all requests) and requiring a device reboot to restore functionality.

Summary generated and translated by AI from the official description.
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC22.1-E.D, PXC36-E.D, PXC36.1-E.D with activated web server (All firmware versions < V6.00.320). The device contains a vulnerability that could allow an attacker to cause a denial of service condition on the device's web server by sending a specially crafted HTTP message to the web server port (tcp/80). The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device's web service. While the device itself stays operational, the web server responds with HTTP status code 404 (Not found) to any further request. A reboot is required to recover the web interface. At the time of advisory publication no public exploitation of this security vulnerability was known.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →