CVE-2019-6806
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon Premium | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon Quantum | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.10 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.90 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M580 | All versions |
References (4)
Source: cybersecurity@se.com
MitigationVendor Advisory
Source: cybersecurity@se.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.