← Back

CVE-2019-6806

nvd nist
Published: May 22, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.

Affected (4)

Modicon Premium Firmware
Modicon Quantum Firmware
Modicon M340 Firmware
Modicon M580 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Schneider Electric
Modicon Premium
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Schneider Electric
Modicon Quantum
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.10
Running on/withPlatform Versions
Schneider Electric
Modicon M340
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.90
Running on/withPlatform Versions
Schneider Electric
Modicon M580
All versions

References (4)

Source: cybersecurity@se.com
MitigationVendor Advisory
Source: cybersecurity@se.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.