HIGH · 7.5

CVE-2019-6819

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the produc...

Vulnerability Description

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the products: Modicon M340 - firmware versions prior to V3.01, Modicon M580 - firmware versions prior to V2.80, All firmware versions of Modicon Quantum and Modicon Premium.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Schneider-ElectricModicon M340 Firmware< 3.01
Schneider-ElectricModicon M340 Bmxp341000-
Schneider-ElectricModicon M340 Bmxp341000H-
Schneider-ElectricModicon M340 Bmxp342000-
Schneider-ElectricModicon M340 Bmxp3420102-
Schneider-ElectricModicon M340 Bmxp3420102Cl-
Schneider-ElectricModicon M340 Bmxp342020-
Schneider-ElectricModicon M340 Bmxp342020H-
Schneider-ElectricModicon M340 Bmxp3420302-
Schneider-ElectricModicon M340 Bmxp3420302Cl-
Schneider-ElectricModicon M340 Bmxp3420302H-
Schneider-ElectricModicon M580 Firmware< 2.80
Schneider-ElectricBmeh582040-
Schneider-ElectricBmeh582040C-
Schneider-ElectricBmeh584040-
Schneider-ElectricBmeh584040C-
Schneider-ElectricBmeh586040-
Schneider-ElectricBmeh586040C-
Schneider-ElectricModicon M580 Bmep581020-
Schneider-ElectricModicon M580 Bmep581020H-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6819?

CVE-2019-6819 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the produc...

How severe is CVE-2019-6819?

CVE-2019-6819 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6819?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M340 Firmware, Schneider-Electric Modicon M340 Bmxp341000, Schneider-Electric Modicon M340 Bmxp341000H, Schneider-Electric Modicon M340 Bmxp342000, Schneider-Electric Modicon M340 Bmxp3420102.