CVE-2019-13926: Siemens Scalance s602 Firmware

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port 443/tcp of affected devices could cause a Denial-of-Service condition of the web server. A cold reboot is required to restore the functionality of the device.

Affected products

  • Siemens Scalance s602 Firmware: from 3.0, before 4.1 (fixed in 4.1)
  • Siemens Scalance s612 Firmware: from 3.0, before 4.1 (fixed in 4.1)
  • Siemens Scalance s623 Firmware: from 3.0, before 4.1 (fixed in 4.1)
  • Siemens Scalance s627-2m Firmware: from 3.0, before 4.1 (fixed in 4.1)

Published 2020-02-11. Last modified 2026-06-17.