HIGH · 8.2

CVE-2019-6820

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specif...

Vulnerability Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
Schneider-ElectricModicon M100 FirmwareAll versions
Schneider-ElectricModicon M100-
Schneider-ElectricModicon M200 FirmwareAll versions
Schneider-ElectricModicon M200-
Schneider-ElectricModicon M221 FirmwareAll versions
Schneider-ElectricModicon M221-
Schneider-ElectricAtv Imc Drive Controller FirmwareAll versions
Schneider-ElectricAtv Imc Drive Controller-
Schneider-ElectricModicon M241 FirmwareAll versions
Schneider-ElectricModicon M241-
Schneider-ElectricModicon M251 FirmwareAll versions
Schneider-ElectricModicon M251-
Schneider-ElectricModicon M258 FirmwareAll versions
Schneider-ElectricModicon M258-
Schneider-ElectricModicon Lmc058 FirmwareAll versions
Schneider-ElectricModicon Lmc058-
Schneider-ElectricModicon Lmc078 FirmwareAll versions
Schneider-ElectricModicon Lmc078-
Schneider-ElectricPacdrive Eco FirmwareAll versions
Schneider-ElectricPacdrive Eco-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6820?

CVE-2019-6820 is a vulnerability with a CVSS score of 8.2 (HIGH). A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specif...

How severe is CVE-2019-6820?

CVE-2019-6820 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6820?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M100 Firmware, Schneider-Electric Modicon M100, Schneider-Electric Modicon M200 Firmware, Schneider-Electric Modicon M200, Schneider-Electric Modicon M221 Firmware.