Vulnerability Description
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M580 Firmware | All versions |
| Schneider-Electric | Modicon M580 | - |
| Schneider-Electric | Modicon M340 Firmware | All versions |
| Schneider-Electric | Modicon M340 | - |
| Schneider-Electric | Modicon Bmxcra Firmware | All versions |
| Schneider-Electric | Modicon Bmxcra | - |
| Schneider-Electric | Modicon 140Cra Firmware | All versions |
| Schneider-Electric | Modicon 140Cra | - |
Related Weaknesses (CWE)
References
- https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-281-02Vendor Advisory
- https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-281-02Vendor Advisory
FAQ
What is CVE-2019-6846?
CVE-2019-6846 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information ...
How severe is CVE-2019-6846?
CVE-2019-6846 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6846?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M580 Firmware, Schneider-Electric Modicon M580, Schneider-Electric Modicon M340 Firmware, Schneider-Electric Modicon M340, Schneider-Electric Modicon Bmxcra Firmware.