A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (All versions < V8.2 Upd12), SIMATIC BATCH V9.0 (All versions < V9.0 SP1 Upd5), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Update 1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC Route Control V8.1 (All versions), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions < V9.0 Upd4), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC (TIA Portal) V15.1 (All versions < V15.1 Update 5), SIMATIC WinCC (TIA Portal) V16 (All versions < V16 Update 1), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 1). Through specially crafted messages, when encrypted communication is enabled, an attacker with network access could use the vulnerability to compromise the availability of the system by causing a Denial-of-Service condition. Successful exploitation requires no system privileges and no user interaction.
Conclusion & alert: CVE-2019-19282 is rated Moderate Risk (54.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.31%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.55% | 1.31% | +0.76% |
| 2 | 2025-11-21 | 0.37% | 0.55% | +0.18% |
| 3 | 2025-11-18 | — | 0.37% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.1 | 2.0 | HIGH |
|
8.6 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| siemens | openpcs_7 | 9.0 | cpe:2.3:a:siemens:openpcs_7:9.0:-:*:*:*:*:*:* |
| siemens | openpcs_7 | 9.0_update_1 | cpe:2.3:a:siemens:openpcs_7:9.0_update_1:*:*:*:*:*:*:* |
| siemens | simatic_batch | 9.0 | cpe:2.3:a:siemens:simatic_batch:9.0:-:*:*:*:*:*:* |
| siemens | simatic_batch | 9.0 | cpe:2.3:a:siemens:simatic_batch:9.0:sp1:*:*:*:*:*:* |
| siemens | simatic_batch | 9.0 | cpe:2.3:a:siemens:simatic_batch:9.0:sp1_update_1:*:*:*:*:*:* |
| siemens | simatic_batch | 9.0 | cpe:2.3:a:siemens:simatic_batch:9.0:sp1_update_2:*:*:*:*:*:* |
| siemens | simatic_batch | 9.0 | cpe:2.3:a:siemens:simatic_batch:9.0:sp1_update_3:*:*:*:*:*:* |
| siemens | simatic_batch | 9.0 | cpe:2.3:a:siemens:simatic_batch:9.0:sp1_update_4:*:*:*:*:*:* |
| siemens | simatic_net_pc | < 16 | cpe:2.3:a:siemens:simatic_net_pc:*:*:*:*:*:*:*:* |
| siemens | simatic_net_pc | 16 | cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:* |
| siemens | simatic_pcs_7 | 8.1 | cpe:2.3:a:siemens:simatic_pcs_7:8.1:*:*:*:*:*:*:* |
| siemens | simatic_pcs_7 | 8.2 | cpe:2.3:a:siemens:simatic_pcs_7:8.2:*:*:*:*:*:*:* |
| siemens | simatic_pcs_7 | 9.0 | cpe:2.3:a:siemens:simatic_pcs_7:9.0:-:*:*:*:*:*:* |
| siemens | simatic_pcs_7 | 9.0 | cpe:2.3:a:siemens:simatic_pcs_7:9.0:sp1:*:*:*:*:*:* |
| siemens | simatic_pcs_7 | 9.0 | cpe:2.3:a:siemens:simatic_pcs_7:9.0:sp2:*:*:*:*:*:* |
| siemens | simatic_route_control | < 9.0 | cpe:2.3:a:siemens:simatic_route_control:*:*:*:*:*:*:*:* |
| siemens | simatic_route_control | 9.0 | cpe:2.3:a:siemens:simatic_route_control:9.0:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_1:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_10:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_11:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_12:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_13:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_2:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_3:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_4:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_5:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_6:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_7:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_8:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update_9:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.5 | cpe:2.3:a:siemens:simatic_wincc:7.5:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.5 | cpe:2.3:a:siemens:simatic_wincc:7.5:sp1:-:*:*:*:*:* |
| siemens | simatic_wincc | 7.5.1 | cpe:2.3:a:siemens:simatic_wincc:7.5.1:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 13 | cpe:2.3:a:siemens:simatic_wincc:13:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 13 | cpe:2.3:a:siemens:simatic_wincc:13:sp1:*:*:*:*:*:* |
| siemens | simatic_wincc | 14.0.1 | cpe:2.3:a:siemens:simatic_wincc:14.0.1:*:*:*:*:*:*:* |
| siemens | simatic_wincc | 15.1 | cpe:2.3:a:siemens:simatic_wincc:15.1:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 15.1 | cpe:2.3:a:siemens:simatic_wincc:15.1:update_1:*:*:*:*:*:* |
| siemens | simatic_wincc | 15.1 | cpe:2.3:a:siemens:simatic_wincc:15.1:update_2:*:*:*:*:*:* |
| siemens | simatic_wincc | 15.1 | cpe:2.3:a:siemens:simatic_wincc:15.1:update_3:*:*:*:*:*:* |
| siemens | simatic_wincc | 15.1 | cpe:2.3:a:siemens:simatic_wincc:15.1:update_4:*:*:*:*:*:* |
| siemens | simatic_wincc | 16 | cpe:2.3:a:siemens:simatic_wincc:16:-:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-270778.pdf | Vendor Advisory |