Vulnerability Description
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when writing specific physical memory blocks using Modbus TCP.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M580 Firmware | < 2.80 |
| Schneider-Electric | Modicon M580 | - |
| Schneider-Electric | Modicon M340 Firmware | < 3.01 |
| Schneider-Electric | Modicon M340 | - |
| Schneider-Electric | Tsxh5744M Firmware | < 3.20 |
| Schneider-Electric | Tsxh5744M | - |
| Schneider-Electric | Tsxh5724M Firmware | < 3.20 |
| Schneider-Electric | Tsxh5724M | - |
| Schneider-Electric | Tsxp576634M Firmware | < 3.20 |
| Schneider-Electric | Tsxp576634M | - |
| Schneider-Electric | Tsxp57554M Firmware | < 3.20 |
| Schneider-Electric | Tsxp57554M | - |
| Schneider-Electric | Tsxp575634M Firmware | < 3.20 |
| Schneider-Electric | Tsxp575634M | - |
| Schneider-Electric | Tsxp57454M Firmware | < 3.20 |
| Schneider-Electric | Tsxp57454M | - |
| Schneider-Electric | Tsxp574634M Firmware | < 3.20 |
| Schneider-Electric | Tsxp574634M | - |
| Schneider-Electric | Tsxp57354M Firmware | < 3.20 |
| Schneider-Electric | Tsxp57354M | - |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2019-344-01Vendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-016-01Third Party AdvisoryUS Government Resource
- https://www.se.com/ww/en/download/document/SEVD-2019-344-01Vendor Advisory
- https://www.us-cert.gov/ics/advisories/icsa-20-016-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-6856?
CVE-2019-6856 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) w...
How severe is CVE-2019-6856?
CVE-2019-6856 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6856?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M580 Firmware, Schneider-Electric Modicon M580, Schneider-Electric Modicon M340 Firmware, Schneider-Electric Modicon M340, Schneider-Electric Tsxh5744M Firmware.