9.8
CRITICAL
CVE-2019-16670
Weidmueller Authentication Brute Force Vulnerability
Description

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.

INFO

Published Date :

Dec. 6, 2019, 6:15 p.m.

Last Modified :

Nov. 21, 2024, 4:30 a.m.

Remotely Exploitable :

Yes !

Impact Score :

5.9

Exploitability Score :

3.9
Affected Products

The following products are affected by CVE-2019-16670 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Weidmueller ie-sw-pl09m-5gc-4gt_firmware
2 Weidmueller ie-sw-pl09mt-5gc-4gt_firmware
3 Weidmueller ie-sw-pl18m-2gc-16tx_firmware
4 Weidmueller ie-sw-pl18mt-2gc-16tx_firmware
5 Weidmueller ie-sw-pl18m-2gc14tx2sc_firmware
6 Weidmueller ie-sw-pl18mt-2gc14tx2sc_firmware
7 Weidmueller ie-sw-pl18m-2gc14tx2st_firmware
8 Weidmueller ie-sw-pl18mt-2gc14tx2st_firmware
9 Weidmueller ie-sw-pl18m-2gc14tx2scs_firmware
10 Weidmueller ie-sw-pl18mt-2gc14tx2scs_firmware
11 Weidmueller ie-sw-pl16m-16tx_firmware
12 Weidmueller ie-sw-pl16mt-16tx_firmware
13 Weidmueller ie-sw-pl16m-14tx-2sc_firmware
14 Weidmueller ie-sw-pl16mt-14tx-2sc_firmware
15 Weidmueller ie-sw-pl16m-14tx-2st_firmware
16 Weidmueller ie-sw-pl16mt-14tx-2st_firmware
17 Weidmueller ie-sw-vl05m-5tx_firmware
18 Weidmueller ie-sw-vl05mt-5tx_firmware
19 Weidmueller ie-sw-vl05m-3tx-2sc_firmware
20 Weidmueller ie-sw-vl05mt-3tx-2sc_firmware
21 Weidmueller ie-sw-vl05m-3tx-2st_firmware
22 Weidmueller ie-sw-vl05mt-3tx-2st_firmware
23 Weidmueller ie-sw-vl08mt-8tx_firmware
24 Weidmueller ie-sw-vl08mt-5tx-3sc_firmware
25 Weidmueller ie-sw-vl08mt-5tx-1sc-2scs_firmware
26 Weidmueller ie-sw-vl08mt-6tx-2st_firmware
27 Weidmueller ie-sw-vl08mt-6tx-2sc_firmware
28 Weidmueller ie-sw-vl08mt-6tx-2scs_firmware
29 Weidmueller ie-sw-pl08m-8tx_firmware
30 Weidmueller ie-sw-pl08mt-8tx_firmware
31 Weidmueller ie-sw-pl08m-6tx-2sc_firmware
32 Weidmueller ie-sw-pl08mt-6tx-2sc_firmware
33 Weidmueller ie-sw-pl08m-6tx-2st_firmware
34 Weidmueller ie-sw-pl08mt-6tx-2st_firmware
35 Weidmueller ie-sw-pl08m-6tx-2scs_firmware
36 Weidmueller ie-sw-pl08mt-6tx-2scs_firmware
37 Weidmueller ie-sw-pl10m-3gt-7tx_firmware
38 Weidmueller ie-sw-pl10mt-3gt-7tx_firmware
39 Weidmueller ie-sw-pl10m-1gt-2gs-7tx_firmware
40 Weidmueller ie-sw-pl10mt-1gt-2gs-7tx_firmware
41 Weidmueller ie-sw-pl09m-5gc-4gt
42 Weidmueller ie-sw-pl09mt-5gc-4gt
43 Weidmueller ie-sw-pl18m-2gc-16tx
44 Weidmueller ie-sw-pl18mt-2gc-16tx
45 Weidmueller ie-sw-pl18m-2gc14tx2sc
46 Weidmueller ie-sw-pl18mt-2gc14tx2sc
47 Weidmueller ie-sw-pl18m-2gc14tx2st
48 Weidmueller ie-sw-pl18mt-2gc14tx2st
49 Weidmueller ie-sw-pl18m-2gc14tx2scs
50 Weidmueller ie-sw-pl18mt-2gc14tx2scs
51 Weidmueller ie-sw-pl16m-16tx
52 Weidmueller ie-sw-pl16mt-16tx
53 Weidmueller ie-sw-pl16m-14tx-2sc
54 Weidmueller ie-sw-pl16mt-14tx-2sc
55 Weidmueller ie-sw-pl16m-14tx-2st
56 Weidmueller ie-sw-pl16mt-14tx-2st
57 Weidmueller ie-sw-vl05m-5tx
58 Weidmueller ie-sw-vl05mt-5tx
59 Weidmueller ie-sw-vl05m-3tx-2sc
60 Weidmueller ie-sw-vl05mt-3tx-2sc
61 Weidmueller ie-sw-vl05m-3tx-2st
62 Weidmueller ie-sw-vl05mt-3tx-2st
63 Weidmueller ie-sw-vl08mt-8tx
64 Weidmueller ie-sw-vl08mt-5tx-3sc
65 Weidmueller ie-sw-vl08mt-5tx-1sc-2scs
66 Weidmueller ie-sw-vl08mt-6tx-2st
67 Weidmueller ie-sw-vl08mt-6tx-2sc
68 Weidmueller ie-sw-vl08mt-6tx-2scs
69 Weidmueller ie-sw-pl08m-8tx
70 Weidmueller ie-sw-pl08mt-8tx
71 Weidmueller ie-sw-pl08m-6tx-2sc
72 Weidmueller ie-sw-pl08mt-6tx-2sc
73 Weidmueller ie-sw-pl08m-6tx-2st
74 Weidmueller ie-sw-pl08mt-6tx-2st
75 Weidmueller ie-sw-pl08m-6tx-2scs
76 Weidmueller ie-sw-pl08mt-6tx-2scs
77 Weidmueller ie-sw-pl10m-3gt-7tx
78 Weidmueller ie-sw-pl10mt-3gt-7tx
79 Weidmueller ie-sw-pl10m-1gt-2gs-7tx
80 Weidmueller ie-sw-pl10mt-1gt-2gs-7tx
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2019-16670.

URL Resource
https://cert.vde.com/en-us/advisories Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2019-018 Third Party Advisory
https://mdcop.weidmueller.com/mediadelivery/asset/900_102694 Vendor Advisory
https://www.us-cert.gov/ics/advisories/icsa-19-339-02 Third Party Advisory
https://cert.vde.com/en-us/advisories Third Party Advisory
https://cert.vde.com/en-us/advisories/vde-2019-018 Third Party Advisory
https://mdcop.weidmueller.com/mediadelivery/asset/900_102694 Vendor Advisory
https://www.us-cert.gov/ics/advisories/icsa-19-339-02 Third Party Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2019-16670 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2019-16670 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://cert.vde.com/en-us/advisories
    Added Reference https://cert.vde.com/en-us/advisories/vde-2019-018
    Added Reference https://mdcop.weidmueller.com/mediadelivery/asset/900_102694
    Added Reference https://www.us-cert.gov/ics/advisories/icsa-19-339-02
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • Initial Analysis by [email protected]

    Dec. 12, 2019

    Action Type Old Value New Value
    Added CVSS V2 NIST (AV:N/AC:L/Au:N/C:P/I:P/A:P)
    Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type https://cert.vde.com/en-us/advisories No Types Assigned https://cert.vde.com/en-us/advisories Third Party Advisory
    Changed Reference Type https://cert.vde.com/en-us/advisories/vde-2019-018 No Types Assigned https://cert.vde.com/en-us/advisories/vde-2019-018 Third Party Advisory
    Changed Reference Type https://mdcop.weidmueller.com/mediadelivery/asset/900_102694 No Types Assigned https://mdcop.weidmueller.com/mediadelivery/asset/900_102694 Vendor Advisory
    Changed Reference Type https://www.us-cert.gov/ics/advisories/icsa-19-339-02 No Types Assigned https://www.us-cert.gov/ics/advisories/icsa-19-339-02 Third Party Advisory
    Added CWE NIST CWE-307
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl09m-5gc-4gt_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.4 OR cpe:2.3:h:weidmueller:ie-sw-pl09m-5gc-4gt:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl09mt-5gc-4gt_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.4 OR cpe:2.3:h:weidmueller:ie-sw-pl09mt-5gc-4gt:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18m-2gc-16tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18m-2gc-16tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18mt-2gc-16tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18mt-2gc-16tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18m-2gc14tx2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18m-2gc14tx2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18mt-2gc14tx2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18mt-2gc14tx2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18m-2gc14tx2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18m-2gc14tx2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18mt-2gc14tx2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18mt-2gc14tx2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18m-2gc14tx2scs_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18m-2gc14tx2scs:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl18mt-2gc14tx2scs_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.4 OR cpe:2.3:h:weidmueller:ie-sw-pl18mt-2gc14tx2scs:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl16m-16tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.2 OR cpe:2.3:h:weidmueller:ie-sw-pl16m-16tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl16mt-16tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.2 OR cpe:2.3:h:weidmueller:ie-sw-pl16mt-16tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl16m-14tx-2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.2 OR cpe:2.3:h:weidmueller:ie-sw-pl16m-14tx-2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl16mt-14tx-2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.2 OR cpe:2.3:h:weidmueller:ie-sw-pl16mt-14tx-2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl16m-14tx-2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.2 OR cpe:2.3:h:weidmueller:ie-sw-pl16m-14tx-2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl16mt-14tx-2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.4.2 OR cpe:2.3:h:weidmueller:ie-sw-pl16mt-14tx-2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl05m-5tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.6.6 OR cpe:2.3:h:weidmueller:ie-sw-vl05m-5tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl05mt-5tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.6.6 OR cpe:2.3:h:weidmueller:ie-sw-vl05mt-5tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl05m-3tx-2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.6.6 OR cpe:2.3:h:weidmueller:ie-sw-vl05m-3tx-2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl05mt-3tx-2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.6.6 OR cpe:2.3:h:weidmueller:ie-sw-vl05mt-3tx-2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl05m-3tx-2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.6.6 OR cpe:2.3:h:weidmueller:ie-sw-vl05m-3tx-2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl05mt-3tx-2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.6.6 OR cpe:2.3:h:weidmueller:ie-sw-vl05mt-3tx-2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl08mt-8tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.5.2 OR cpe:2.3:h:weidmueller:ie-sw-vl08mt-8tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl08mt-5tx-3sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.5.2 OR cpe:2.3:h:weidmueller:ie-sw-vl08mt-5tx-3sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl08mt-5tx-1sc-2scs_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.5.2 OR cpe:2.3:h:weidmueller:ie-sw-vl08mt-5tx-1sc-2scs:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl08mt-6tx-2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.5.2 OR cpe:2.3:h:weidmueller:ie-sw-vl08mt-6tx-2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl08mt-6tx-2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.5.2 OR cpe:2.3:h:weidmueller:ie-sw-vl08mt-6tx-2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-vl08mt-6tx-2scs_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.5.2 OR cpe:2.3:h:weidmueller:ie-sw-vl08mt-6tx-2scs:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08m-8tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08m-8tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08mt-8tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08mt-8tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08m-6tx-2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08m-6tx-2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08mt-6tx-2sc_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08mt-6tx-2sc:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08m-6tx-2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08m-6tx-2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08mt-6tx-2st_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08mt-6tx-2st:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08m-6tx-2scs_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08m-6tx-2scs:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl08mt-6tx-2scs_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.8 OR cpe:2.3:h:weidmueller:ie-sw-pl08mt-6tx-2scs:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl10m-3gt-7tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.16 OR cpe:2.3:h:weidmueller:ie-sw-pl10m-3gt-7tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl10mt-3gt-7tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.16 OR cpe:2.3:h:weidmueller:ie-sw-pl10mt-3gt-7tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl10m-1gt-2gs-7tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.16 OR cpe:2.3:h:weidmueller:ie-sw-pl10m-1gt-2gs-7tx:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:weidmueller:ie-sw-pl10mt-1gt-2gs-7tx_firmware:*:*:*:*:*:*:*:* versions up to (including) 3.3.16 OR cpe:2.3:h:weidmueller:ie-sw-pl10mt-1gt-2gs-7tx:-:*:*:*:*:*:*:*
  • CVE Modified by [email protected]

    Dec. 10, 2019

    Action Type Old Value New Value
    Added Reference https://www.us-cert.gov/ics/advisories/icsa-19-339-02 [No Types Assigned]
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2019-16670 is associated with the following CWEs:

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.47 }} -0.19%

score

0.63240

percentile

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
© cvefeed.io
Latest DB Update: Jul. 18, 2025 15:14