Vulnerability Description
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M580 Firmware | - |
| Schneider-Electric | Modicon M580 | - |
| Schneider-Electric | Modicon Bmenoc 0311 Firmware | - |
| Schneider-Electric | Modicon Bmenoc 0311 | - |
| Schneider-Electric | Modicon Bmenoc 0321 Firmware | - |
| Schneider-Electric | Modicon Bmenoc 0321 | - |
Related Weaknesses (CWE)
References
- https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-281-04Vendor Advisory
- https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-281-04Vendor Advisory
FAQ
What is CVE-2019-6849?
CVE-2019-6849 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus...
How severe is CVE-2019-6849?
CVE-2019-6849 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6849?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M580 Firmware, Schneider-Electric Modicon M580, Schneider-Electric Modicon Bmenoc 0311 Firmware, Schneider-Electric Modicon Bmenoc 0311, Schneider-Electric Modicon Bmenoc 0321 Firmware.