Lucene search

K
cve[email protected]CVE-2019-6828
HistorySep 17, 2019 - 8:15 p.m.

CVE-2019-6828

2019-09-1720:15:12
CWE-755
CWE-248
web.nvd.nist.gov
86
cve-2019-6828
nvd
cwe-248
modicon m580
modicon m340
modicon premium
modicon quantum
firmware
denial of service
modbus

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

42.6%

A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.

Affected configurations

NVD
Node
schneider-electricmodicon_m580_firmwareRange<2.90
AND
schneider-electricmodicon_m580Match-
Node
schneider-electricmodicon_m340_firmwareRange<3.10
AND
schneider-electricmodicon_m340Match-
Node
schneider-electricmodicon_premium_firmware
AND
schneider-electricmodicon_premiumMatch-
Node
schneider-electricmodicon_quantum_firmware
AND
schneider-electricmodicon_quantumMatch-

CNA Affected

[
  {
    "product": "Modicon M580",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "firmware version prior to V2.90"
      }
    ]
  },
  {
    "product": "Modicon M340",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "firmware version prior to V3.10"
      }
    ]
  },
  {
    "product": "Modicon Premium",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "all versions"
      }
    ]
  },
  {
    "product": "Modicon Quantum",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "all versions"
      }
    ]
  }
]

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

42.6%

Related for CVE-2019-6828