A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain a vulnerability that could allow an unauthenticated attacker to trigger a denial-of-service condition. The vulnerability can be triggered if a large HTTP request is sent to the executing service. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the service provided by the software.
Conclusion & alert: CVE-2019-13921 is rated Moderate Risk (54.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.37%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.44% | 1.37% | +0.93% |
| 2 | 2025-03-30 | 0.68% | 0.44% | -0.24% |
| 3 | 2025-03-29 | — | 0.68% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| siemens | simatic_winac_rtx_\(f\)_2010 | — | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:*:*:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | — | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:-:*:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | — | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:-:update_1:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | — | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:-:update_2:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | — | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:-:update_3:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | sp1 | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:sp1:*:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | sp2 | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:sp2:-:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | sp2 | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:sp2:update_1:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | sp2 | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:sp2:update_2:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | sp2 | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:sp2:update_3:*:*:*:*:*:* |
| siemens | simatic_winac_rtx_\(f\)_2010 | sp2 | cpe:2.3:a:siemens:simatic_winac_rtx_\(f\)_2010:sp2:update_4:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-878278.pdf | Vendor Advisory |