HIGH · 7.5

CVE-2019-6850

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific regi...

Vulnerability Description

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Schneider-ElectricModicon M580 Firmware-
Schneider-ElectricModicon M580-
Schneider-ElectricModicon Bmenoc 0311 Firmware-
Schneider-ElectricModicon Bmenoc 0311-
Schneider-ElectricModicon Bmenoc 0321 Firmware-
Schneider-ElectricModicon Bmenoc 0321-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6850?

CVE-2019-6850 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific regi...

How severe is CVE-2019-6850?

CVE-2019-6850 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6850?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M580 Firmware, Schneider-Electric Modicon M580, Schneider-Electric Modicon Bmenoc 0311 Firmware, Schneider-Electric Modicon Bmenoc 0311, Schneider-Electric Modicon Bmenoc 0321 Firmware.