Vulnerability Description
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the products: Modicon M340 - firmware versions prior to V3.01, Modicon M580 - firmware versions prior to V2.80, All firmware versions of Modicon Quantum and Modicon Premium.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M340 Firmware | < 3.01 |
| Schneider-Electric | Modicon M340 Bmxp341000 | - |
| Schneider-Electric | Modicon M340 Bmxp341000H | - |
| Schneider-Electric | Modicon M340 Bmxp342000 | - |
| Schneider-Electric | Modicon M340 Bmxp3420102 | - |
| Schneider-Electric | Modicon M340 Bmxp3420102Cl | - |
| Schneider-Electric | Modicon M340 Bmxp342020 | - |
| Schneider-Electric | Modicon M340 Bmxp342020H | - |
| Schneider-Electric | Modicon M340 Bmxp3420302 | - |
| Schneider-Electric | Modicon M340 Bmxp3420302Cl | - |
| Schneider-Electric | Modicon M340 Bmxp3420302H | - |
| Schneider-Electric | Modicon M580 Firmware | < 2.80 |
| Schneider-Electric | Bmeh582040 | - |
| Schneider-Electric | Bmeh582040C | - |
| Schneider-Electric | Bmeh584040 | - |
| Schneider-Electric | Bmeh584040C | - |
| Schneider-Electric | Bmeh586040 | - |
| Schneider-Electric | Bmeh586040C | - |
| Schneider-Electric | Modicon M580 Bmep581020 | - |
| Schneider-Electric | Modicon M580 Bmep581020H | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/109004Broken Link
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-05/Vendor Advisory
- http://www.securityfocus.com/bid/109004Broken Link
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-05/Vendor Advisory
FAQ
What is CVE-2019-6819?
CVE-2019-6819 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the produc...
How severe is CVE-2019-6819?
CVE-2019-6819 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6819?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M340 Firmware, Schneider-Electric Modicon M340 Bmxp341000, Schneider-Electric Modicon M340 Bmxp341000H, Schneider-Electric Modicon M340 Bmxp342000, Schneider-Electric Modicon M340 Bmxp3420102.