HIGH · 8.6

CVE-2019-6848

A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version i...

Vulnerability Description

A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Schneider-ElectricModicon M580 Firmware-
Schneider-ElectricModicon M580-
Schneider-ElectricModicon Bmenoc 0311 Firmware-
Schneider-ElectricModicon Bmenoc 0311-
Schneider-ElectricModicon Bmenoc 0321 Firmware-
Schneider-ElectricModicon Bmenoc 0321-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6848?

CVE-2019-6848 is a vulnerability with a CVSS score of 8.6 (HIGH). A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version i...

How severe is CVE-2019-6848?

CVE-2019-6848 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6848?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M580 Firmware, Schneider-Electric Modicon M580, Schneider-Electric Modicon Bmenoc 0311 Firmware, Schneider-Electric Modicon Bmenoc 0311, Schneider-Electric Modicon Bmenoc 0321 Firmware.