Search

Find a vulnerability

Search criteria

    4 vulnerabilities found for SINEMA Server by Siemens

    CVE-2019-10941 (GCVE-0-2019-10941)

    Vulnerability from cvelistv5 – Published: 2021-09-14 10:47 – Updated: 2024-08-04 22:40
    VLAI
    Summary
    A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges.
    Severity
    No CVSS data available.
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    References
    Impacted products
    Vendor Product Version
    Siemens SINEMA Server Affected: All versions < V14 SP3
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:40:15.255Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-835377.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "SINEMA Server",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14 SP3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been identified in SINEMA Server (All versions \u003c V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306: Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-09-14T10:47:02.000Z",
            "orgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
            "shortName": "siemens"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-835377.pdf"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "productcert@siemens.com",
              "ID": "CVE-2019-10941",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "SINEMA Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V14 SP3"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Siemens"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability has been identified in SINEMA Server (All versions \u003c V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an attacker to obtain encoded system configuration backup files. This is only possible through network access to the affected system, and successful exploitation requires no system privileges."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-306: Missing Authentication for Critical Function"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://cert-portal.siemens.com/productcert/pdf/ssa-835377.pdf",
                  "refsource": "MISC",
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-835377.pdf"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
        "assignerShortName": "siemens",
        "cveId": "CVE-2019-10941",
        "datePublished": "2021-09-14T10:47:02.000Z",
        "dateReserved": "2019-04-08T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:40:15.255Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-25237 (GCVE-0-2020-25237)

    Vulnerability from cvelistv5 – Published: 2021-02-09 15:38 – Updated: 2024-08-04 15:33
    VLAI
    Summary
    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as 'Zip-Slip'. (ZDI-CAN-12054)
    Severity
    No CVSS data available.
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    Siemens SINEC NMS Affected: All versions < V1.0 SP1 Update 1
    Create a notification for this product.
    Siemens SINEMA Server Affected: All versions < V14.0 SP2 Update 2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T15:33:05.612Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-156833.pdf"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-040-03"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-253/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "SINEC NMS",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V1.0 SP1 Update 1"
                }
              ]
            },
            {
              "product": "SINEMA Server",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14.0 SP2 Update 2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been identified in SINEC NMS (All versions \u003c V1.0 SP1 Update 1), SINEMA Server (All versions \u003c V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as \u0027Zip-Slip\u0027. (ZDI-CAN-12054)"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-02-25T18:06:20.000Z",
            "orgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
            "shortName": "siemens"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-156833.pdf"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-040-03"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-253/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "productcert@siemens.com",
              "ID": "CVE-2020-25237",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "SINEC NMS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V1.0 SP1 Update 1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SINEMA Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V14.0 SP2 Update 2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Siemens"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability has been identified in SINEC NMS (All versions \u003c V1.0 SP1 Update 1), SINEMA Server (All versions \u003c V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does not correctly check if the relative file path of the extracted files is still within the intended target directory. With this an attacker could create or overwrite arbitrary files on an affected system. This type of vulnerability is also known as \u0027Zip-Slip\u0027. (ZDI-CAN-12054)"
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://cert-portal.siemens.com/productcert/pdf/ssa-156833.pdf",
                  "refsource": "MISC",
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-156833.pdf"
                },
                {
                  "name": "https://us-cert.cisa.gov/ics/advisories/icsa-21-040-03",
                  "refsource": "MISC",
                  "url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-040-03"
                },
                {
                  "name": "https://www.zerodayinitiative.com/advisories/ZDI-21-253/",
                  "refsource": "MISC",
                  "url": "https://www.zerodayinitiative.com/advisories/ZDI-21-253/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
        "assignerShortName": "siemens",
        "cveId": "CVE-2020-25237",
        "datePublished": "2021-02-09T15:38:17.000Z",
        "dateReserved": "2020-09-10T00:00:00.000Z",
        "dateUpdated": "2024-08-04T15:33:05.612Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-7580 (GCVE-0-2020-7580)

    Vulnerability from cvelistv5 – Published: 2020-06-10 00:00 – Updated: 2024-08-04 09:33
    VLAI
    Summary
    A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Software Controller (All versions < V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMATIC STEP 7 V5 (All versions < V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions < V3.16 P018), SIMATIC WinCC OA V3.17 (All versions < V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Update 5), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 3), SINAMICS STARTER (All Versions < V5.4 HF2), SINAMICS Startdrive (All Versions < V16 Update 3), SINEC NMS (All versions < V1.0 SP2), SINEMA Server (All versions < V14 SP3), SINUMERIK ONE virtual (All Versions < V6.14), SINUMERIK Operate (All Versions < V6.14). A common component used by the affected applications regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to execute arbitrary code with SYTEM privileges.
    Severity
    No CVSS data available.
    CWE
    • CWE-428 - Unquoted Search Path or Element
    Impacted products
    Vendor Product Version
    Siemens SIMATIC Automation Tool Affected: All versions < V4 SP2
    Create a notification for this product.
    Siemens SIMATIC NET PC Software V14 Affected: All versions < V14 SP1 Update 14
    Create a notification for this product.
    Siemens SIMATIC NET PC Software V15 Affected: All versions
    Create a notification for this product.
    Siemens SIMATIC NET PC Software V16 Affected: All versions < V16 Upd3
    Create a notification for this product.
    Siemens SIMATIC PCS neo Affected: All versions < V3.0 SP1
    Create a notification for this product.
    Siemens SIMATIC ProSave Affected: All versions < V17
    Create a notification for this product.
    Siemens SIMATIC S7-1500 Software Controller Affected: All versions < V21.8
    Create a notification for this product.
    Siemens SIMATIC STEP 7 (TIA Portal) V13 Affected: All versions < V13 SP2 Update 4
    Create a notification for this product.
    Siemens SIMATIC STEP 7 (TIA Portal) V14 Affected: All versions < V14 SP1 Update 10
    Create a notification for this product.
    Siemens SIMATIC STEP 7 (TIA Portal) V15 Affected: All versions < V15.1 Update 5
    Create a notification for this product.
    Siemens SIMATIC STEP 7 (TIA Portal) V16 Affected: All versions < V16 Update 2
    Create a notification for this product.
    Siemens SIMATIC STEP 7 V5 Affected: All versions < V5.6 SP2 HF3
    Create a notification for this product.
    Siemens SIMATIC WinCC OA V3.16 Affected: All versions < V3.16 P018
    Create a notification for this product.
    Siemens SIMATIC WinCC OA V3.17 Affected: All versions < V3.17 P003
    Create a notification for this product.
    Siemens SIMATIC WinCC Runtime Advanced Affected: All versions < V16 Update 2
    Create a notification for this product.
    Siemens SIMATIC WinCC Runtime Professional V13 Affected: All versions < V13 SP2 Update 4
    Create a notification for this product.
    Siemens SIMATIC WinCC Runtime Professional V14 Affected: All versions < V14 SP1 Update 10
    Create a notification for this product.
    Siemens SIMATIC WinCC Runtime Professional V15 Affected: All versions < V15.1 Update 5
    Create a notification for this product.
    Siemens SIMATIC WinCC Runtime Professional V16 Affected: All versions < V16 Update 2
    Create a notification for this product.
    Siemens SIMATIC WinCC V7.4 Affected: All versions < V7.4 SP1 Update 14
    Create a notification for this product.
    Siemens SIMATIC WinCC V7.5 Affected: All versions < V7.5 SP1 Update 3
    Create a notification for this product.
    Siemens SINAMICS STARTER Affected: All Versions < V5.4 HF2
    Create a notification for this product.
    Siemens SINAMICS Startdrive Affected: All Versions < V16 Update 3
    Create a notification for this product.
    Siemens SINEC NMS Affected: All versions < V1.0 SP2
    Create a notification for this product.
    Siemens SINEMA Server Affected: All versions < V14 SP3
    Create a notification for this product.
    Siemens SINUMERIK ONE virtual Affected: All Versions < V6.14
    Create a notification for this product.
    Siemens SINUMERIK Operate Affected: All Versions < V6.14
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T09:33:19.492Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-312271.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-161-04"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "SIMATIC Automation Tool",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V4 SP2"
                }
              ]
            },
            {
              "product": "SIMATIC NET PC Software V14",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14 SP1 Update 14"
                }
              ]
            },
            {
              "product": "SIMATIC NET PC Software V15",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions"
                }
              ]
            },
            {
              "product": "SIMATIC NET PC Software V16",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V16 Upd3"
                }
              ]
            },
            {
              "product": "SIMATIC PCS neo",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V3.0 SP1"
                }
              ]
            },
            {
              "product": "SIMATIC ProSave",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V17"
                }
              ]
            },
            {
              "product": "SIMATIC S7-1500 Software Controller",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V21.8"
                }
              ]
            },
            {
              "product": "SIMATIC STEP 7 (TIA Portal) V13",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V13 SP2 Update 4"
                }
              ]
            },
            {
              "product": "SIMATIC STEP 7 (TIA Portal) V14",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14 SP1 Update 10"
                }
              ]
            },
            {
              "product": "SIMATIC STEP 7 (TIA Portal) V15",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V15.1 Update 5"
                }
              ]
            },
            {
              "product": "SIMATIC STEP 7 (TIA Portal) V16",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V16 Update 2"
                }
              ]
            },
            {
              "product": "SIMATIC STEP 7 V5",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V5.6 SP2 HF3"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC OA V3.16",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V3.16 P018"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC OA V3.17",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V3.17 P003"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC Runtime Advanced",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V16 Update 2"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC Runtime Professional V13",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V13 SP2 Update 4"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC Runtime Professional V14",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14 SP1 Update 10"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC Runtime Professional V15",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V15.1 Update 5"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC Runtime Professional V16",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V16 Update 2"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC V7.4",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V7.4 SP1 Update 14"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC V7.5",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V7.5 SP1 Update 3"
                }
              ]
            },
            {
              "product": "SINAMICS STARTER",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All Versions \u003c V5.4 HF2"
                }
              ]
            },
            {
              "product": "SINAMICS Startdrive",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All Versions \u003c V16 Update 3"
                }
              ]
            },
            {
              "product": "SINEC NMS",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V1.0 SP2"
                }
              ]
            },
            {
              "product": "SINEMA Server",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14 SP3"
                }
              ]
            },
            {
              "product": "SINUMERIK ONE virtual",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All Versions \u003c V6.14"
                }
              ]
            },
            {
              "product": "SINUMERIK Operate",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All Versions \u003c V6.14"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been identified in SIMATIC Automation Tool (All versions \u003c V4 SP2), SIMATIC NET PC Software V14 (All versions \u003c V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions \u003c V16 Upd3), SIMATIC PCS neo (All versions \u003c V3.0 SP1), SIMATIC ProSave (All versions \u003c V17), SIMATIC S7-1500 Software Controller (All versions \u003c V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions \u003c V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions \u003c V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions \u003c V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions \u003c V16 Update 2), SIMATIC STEP 7 V5 (All versions \u003c V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions \u003c V3.16 P018), SIMATIC WinCC OA V3.17 (All versions \u003c V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions \u003c V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions \u003c V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions \u003c V14 SP1 Update 10), SIMATIC WinCC Runtime Professional V15 (All versions \u003c V15.1 Update 5), SIMATIC WinCC Runtime Professional V16 (All versions \u003c V16 Update 2), SIMATIC WinCC V7.4 (All versions \u003c V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions \u003c V7.5 SP1 Update 3), SINAMICS STARTER (All Versions \u003c V5.4 HF2), SINAMICS Startdrive (All Versions \u003c V16 Update 3), SINEC NMS (All versions \u003c V1.0 SP2), SINEMA Server (All versions \u003c V14 SP3), SINUMERIK ONE virtual (All Versions \u003c V6.14), SINUMERIK Operate (All Versions \u003c V6.14). A common component used by the affected applications regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to execute arbitrary code with SYTEM privileges."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-428",
                  "description": "CWE-428: Unquoted Search Path or Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-12-13T00:00:00.000Z",
            "orgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
            "shortName": "siemens"
          },
          "references": [
            {
              "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-312271.pdf"
            },
            {
              "url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-161-04"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
        "assignerShortName": "siemens",
        "cveId": "CVE-2020-7580",
        "datePublished": "2020-06-10T00:00:00.000Z",
        "dateReserved": "2020-01-21T00:00:00.000Z",
        "dateUpdated": "2024-08-04T09:33:19.492Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-6575 (GCVE-0-2019-6575)

    Vulnerability from cvelistv5 – Published: 2019-04-17 13:40 – Updated: 2026-06-03 13:25
    VLAI
    Summary
    A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Upd 4), SIMATIC IPC DiagMonitor (All versions < V5.1.3), SIMATIC NET PC Software V13 (All versions), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC RF188C (All versions < V1.1.0), SIMATIC RF600R family (All versions < V3.2.1), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions >= V2.5 < V2.6.1), SIMATIC S7-1500 Software Controller (All versions between V2.5 (including) and V2.7 (excluding)), SIMATIC WinCC OA (All versions < V3.15 P018), SIMATIC WinCC Runtime Advanced (All versions < V15.1 Upd 4), SINEC NMS (All versions < V1.0 SP1), SINEMA Server (All versions < V14 SP2), SINUMERIK OPC UA Server (All versions < V2.1), TeleControl Server Basic (All versions < V3.1.1). Specially crafted network packets sent to affected devices on port 4840/tcp could allow an unauthenticated remote attacker to cause a denial of service condition of the OPC communication or crash the device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the OPC communication.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-03 13:20 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Siemens SIMATIC CP 443-1 OPC UA Affected: All versions
    Create a notification for this product.
    Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) Affected: All versions < V2.7
    Create a notification for this product.
    Siemens SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) Affected: All versions < V15.1 Upd 4
    Create a notification for this product.
    Siemens SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants) Affected: All versions < V15.1 Upd 4
    Create a notification for this product.
    Siemens SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F Affected: All versions < V15.1 Upd 4
    Create a notification for this product.
    Siemens SIMATIC IPC DiagMonitor Affected: All versions < V5.1.3
    Create a notification for this product.
    Siemens SIMATIC NET PC Software V13 Affected: All versions
    Create a notification for this product.
    Siemens SIMATIC NET PC Software V14 Affected: All versions < V14 SP1 Update 14
    Create a notification for this product.
    Siemens SIMATIC NET PC Software V15 Affected: All versions
    Create a notification for this product.
    Siemens SIMATIC RF188C Affected: All versions < V1.1.0
    Create a notification for this product.
    Siemens SIMATIC RF600R family Affected: All versions < V3.2.1
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) Affected: All versions >= V2.5 < V2.6.1
    Create a notification for this product.
    Siemens SIMATIC S7-1500 Software Controller Affected: All versions between V2.5 (including) and V2.7 (excluding)
    Create a notification for this product.
    Siemens SIMATIC WinCC OA Affected: All versions < V3.15 P018
    Create a notification for this product.
    Siemens SIMATIC WinCC Runtime Advanced Affected: All versions < V15.1 Upd 4
    Create a notification for this product.
    Siemens SINEC NMS Affected: All versions < V1.0 SP1
    Create a notification for this product.
    Siemens SINEMA Server Affected: All versions < V14 SP2
    Create a notification for this product.
    Siemens SINUMERIK OPC UA Server Affected: All versions < V2.1
    Create a notification for this product.
    Siemens TeleControl Server Basic Affected: All versions < V3.1.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T20:23:22.041Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-307392.pdf"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2019-6575",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-03T13:20:11.329732Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-03T13:25:38.925Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "SIMATIC CP 443-1 OPC UA",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions"
                }
              ]
            },
            {
              "product": "SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V2.7"
                }
              ]
            },
            {
              "product": "SIMATIC HMI Comfort Outdoor Panels 7\" \u0026 15\" (incl. SIPLUS variants)",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V15.1 Upd 4"
                }
              ]
            },
            {
              "product": "SIMATIC HMI Comfort Panels 4\" - 22\" (incl. SIPLUS variants)",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V15.1 Upd 4"
                }
              ]
            },
            {
              "product": "SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V15.1 Upd 4"
                }
              ]
            },
            {
              "product": "SIMATIC IPC DiagMonitor",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V5.1.3"
                }
              ]
            },
            {
              "product": "SIMATIC NET PC Software V13",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions"
                }
              ]
            },
            {
              "product": "SIMATIC NET PC Software V14",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14 SP1 Update 14"
                }
              ]
            },
            {
              "product": "SIMATIC NET PC Software V15",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions"
                }
              ]
            },
            {
              "product": "SIMATIC RF188C",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V1.1.0"
                }
              ]
            },
            {
              "product": "SIMATIC RF600R family",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V3.2.1"
                }
              ]
            },
            {
              "product": "SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003e= V2.5 \u003c V2.6.1"
                }
              ]
            },
            {
              "product": "SIMATIC S7-1500 Software Controller",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions between V2.5 (including) and V2.7 (excluding)"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC OA",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V3.15 P018"
                }
              ]
            },
            {
              "product": "SIMATIC WinCC Runtime Advanced",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V15.1 Upd 4"
                }
              ]
            },
            {
              "product": "SINEC NMS",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V1.0 SP1"
                }
              ]
            },
            {
              "product": "SINEMA Server",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V14 SP2"
                }
              ]
            },
            {
              "product": "SINUMERIK OPC UA Server",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V2.1"
                }
              ]
            },
            {
              "product": "TeleControl Server Basic",
              "vendor": "Siemens",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions \u003c V3.1.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions \u003c V2.7), SIMATIC HMI Comfort Outdoor Panels 7\" \u0026 15\" (incl. SIPLUS variants) (All versions \u003c V15.1 Upd 4), SIMATIC HMI Comfort Panels 4\" - 22\" (incl. SIPLUS variants) (All versions \u003c V15.1 Upd 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions \u003c V15.1 Upd 4), SIMATIC IPC DiagMonitor (All versions \u003c V5.1.3), SIMATIC NET PC Software V13 (All versions), SIMATIC NET PC Software V14 (All versions \u003c V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC RF188C (All versions \u003c V1.1.0), SIMATIC RF600R family (All versions \u003c V3.2.1), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions \u003e= V2.5 \u003c V2.6.1), SIMATIC S7-1500 Software Controller (All versions between V2.5 (including) and V2.7 (excluding)), SIMATIC WinCC OA (All versions \u003c V3.15 P018), SIMATIC WinCC Runtime Advanced (All versions \u003c V15.1 Upd 4), SINEC NMS (All versions \u003c V1.0 SP1), SINEMA Server (All versions \u003c V14 SP2), SINUMERIK OPC UA Server (All versions \u003c V2.1), TeleControl Server Basic (All versions \u003c V3.1.1). Specially crafted network packets sent to affected devices on port 4840/tcp could allow an unauthenticated remote attacker to cause a denial of service condition of the OPC communication or crash the device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the OPC communication."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-248",
                  "description": "CWE-248: Uncaught Exception",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-08-10T11:16:36.000Z",
            "orgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
            "shortName": "siemens"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-307392.pdf"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "productcert@siemens.com",
              "ID": "CVE-2019-6575",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "SIMATIC CP 443-1 OPC UA",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V2.7"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC HMI Comfort Outdoor Panels 7\" \u0026 15\" (incl. SIPLUS variants)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V15.1 Upd 4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC HMI Comfort Panels 4\" - 22\" (incl. SIPLUS variants)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V15.1 Upd 4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V15.1 Upd 4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC IPC DiagMonitor",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V5.1.3"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC NET PC Software V13",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC NET PC Software V14",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V14 SP1 Update 14"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC NET PC Software V15",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC RF188C",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V1.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC RF600R family",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V3.2.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003e= V2.5 \u003c V2.6.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC S7-1500 Software Controller",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions between V2.5 (including) and V2.7 (excluding)"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC WinCC OA",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V3.15 P018"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SIMATIC WinCC Runtime Advanced",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V15.1 Upd 4"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SINEC NMS",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V1.0 SP1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SINEMA Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V14 SP2"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "SINUMERIK OPC UA Server",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V2.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "TeleControl Server Basic",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "All versions \u003c V3.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Siemens"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions \u003c V2.7), SIMATIC HMI Comfort Outdoor Panels 7\" \u0026 15\" (incl. SIPLUS variants) (All versions \u003c V15.1 Upd 4), SIMATIC HMI Comfort Panels 4\" - 22\" (incl. SIPLUS variants) (All versions \u003c V15.1 Upd 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions \u003c V15.1 Upd 4), SIMATIC IPC DiagMonitor (All versions \u003c V5.1.3), SIMATIC NET PC Software V13 (All versions), SIMATIC NET PC Software V14 (All versions \u003c V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC RF188C (All versions \u003c V1.1.0), SIMATIC RF600R family (All versions \u003c V3.2.1), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions \u003e= V2.5 \u003c V2.6.1), SIMATIC S7-1500 Software Controller (All versions between V2.5 (including) and V2.7 (excluding)), SIMATIC WinCC OA (All versions \u003c V3.15 P018), SIMATIC WinCC Runtime Advanced (All versions \u003c V15.1 Upd 4), SINEC NMS (All versions \u003c V1.0 SP1), SINEMA Server (All versions \u003c V14 SP2), SINUMERIK OPC UA Server (All versions \u003c V2.1), TeleControl Server Basic (All versions \u003c V3.1.1). Specially crafted network packets sent to affected devices on port 4840/tcp could allow an unauthenticated remote attacker to cause a denial of service condition of the OPC communication or crash the device. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the OPC communication."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-248: Uncaught Exception"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://cert-portal.siemens.com/productcert/pdf/ssa-307392.pdf",
                  "refsource": "MISC",
                  "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-307392.pdf"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cec7a2ec-15b4-4faf-bd53-b40f371f3a77",
        "assignerShortName": "siemens",
        "cveId": "CVE-2019-6575",
        "datePublished": "2019-04-17T13:40:24.000Z",
        "dateReserved": "2019-01-22T00:00:00.000Z",
        "dateUpdated": "2026-06-03T13:25:38.925Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }