MEDIUM · 6.5

CVE-2019-6833

A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMI...

Vulnerability Description

A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Schneider-ElectricHmigto Firmware-
Schneider-ElectricHmigto1300-
Schneider-ElectricHmigto1310-
Schneider-ElectricHmigto2300-
Schneider-ElectricHmigto2310-
Schneider-ElectricHmigto2315-
Schneider-ElectricHmigto3510-
Schneider-ElectricHmigto4310-
Schneider-ElectricHmigto5310-
Schneider-ElectricHmigto5315-
Schneider-ElectricHmigto6310-
Schneider-ElectricHmigto6315-
Schneider-ElectricHmisto Firmware-
Schneider-ElectricHmisto501-
Schneider-ElectricHmisto511-
Schneider-ElectricHmisto512-
Schneider-ElectricHmisto531-
Schneider-ElectricHmisto532-
Schneider-ElectricHmisto705-
Schneider-ElectricHmisto715-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6833?

CVE-2019-6833 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMI...

How severe is CVE-2019-6833?

CVE-2019-6833 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6833?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Hmigto Firmware, Schneider-Electric Hmigto1300, Schneider-Electric Hmigto1310, Schneider-Electric Hmigto2300, Schneider-Electric Hmigto2310.