Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2019-10953 Details
Description
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026Exploitation: NoneAutomatable: YesTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-19-106-03 | CVE | MitigationThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/108413 | CVE | Third Party AdvisoryVDB Entry |
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2019/icsa-19-106-03.json | [email protected] | |
| https://ics-cert.us-cert.gov/advisories/ICSA-19-106-03 | [email protected] | MitigationThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/108413 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| abb pm554-tp-eth firmware | All versions |
CPE
Remediation
| |
| abb pm554-tp-eth | All versions |
CPE
Remediation
| |
| phoenixcontact ilc 151 eth firmware | All versions |
CPE
Remediation
| |
| phoenixcontact ilc 151 eth | All versions |
CPE
Remediation
| |
| schneider-electric modicon m221 firmware | < 1.10.0.0 |
CPE
Remediation
| |
| schneider-electric modicon m221 | All versions |
CPE
Remediation
| |
| siemens 6es7211-1ae40-0xb0 firmware | All versions |
CPE
Remediation
| |
| siemens 6es7211-1ae40-0xb0 | All versions |
CPE
Remediation
| |
| siemens 6es7314-6eh04-0ab0 firmware | All versions |
CPE
Remediation
| |
| siemens 6es7314-6eh04-0ab0 | All versions |
CPE
Remediation
| |
| siemens 6ed1052-1cc01-0ba8 firmware | All versions |
CPE
Remediation
| |
| siemens 6ed1052-1cc01-0ba8 | All versions |
CPE
Remediation
| |
| wago knx ip firmware | All versions |
CPE
Remediation
| |
| wago knx ip | All versions |
CPE
Remediation
| |
| wago pfc100 firmware | All versions |
CPE
Remediation
| |
| wago pfc100 | All versions |
CPE
Remediation
| |
| wago ethernet firmware | All versions |
CPE
Remediation
| |
| wago ethernet | All versions |
CPE
Remediation
| |
| wago bacnet/ip firmware | All versions |
CPE
Remediation
| |
| wago bacnet/ip | All versions |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | CVE Modified | [email protected] |
| May 29, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 31, 2022 | Reanalysis | [email protected] |
| Jan 31, 2022 | CPE Deprecation Remap | [email protected] |
| Jan 31, 2022 | CPE Deprecation Remap | [email protected] |
| Jan 31, 2022 | CPE Deprecation Remap | [email protected] |
| Jan 31, 2022 | CPE Deprecation Remap | [email protected] |
| Jan 31, 2022 | CPE Deprecation Remap | [email protected] |
| Aug 19, 2021 | CPE Deprecation Remap | [email protected] |
| Aug 19, 2021 | CPE Deprecation Remap | [email protected] |
| Oct 2, 2020 | Modified Analysis | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| May 22, 2019 | CVE Modified | [email protected] |
| Apr 17, 2019 | Initial Analysis | [email protected] |