Lucene search

K
cvelistSchneiderCVELIST:CVE-2019-6820
HistoryMay 22, 2019 - 7:40 p.m.

CVE-2019-6820

2019-05-2219:40:20
CWE-306
schneider
www.cve.org
7

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

42.5%

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2

CNA Affected

[
  {
    "product": "Modicon and PacDrive Controller, All versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Modicon and PacDrive Controller, All versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2"
      }
    ]
  }
]

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

42.5%

Related for CVELIST:CVE-2019-6820