CVE-2019-6549: High severity kunbus pr100088 modbus gateway firmware vulnerability
Published Feb 12, 2019
·Updated
An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
Affected Software
4 affected components
All of the following
Kunbus Pr100088 Modbus Gateway Firmware<r02
Kunbus PR100088 Modbus gateway
Kunbus Pr100088 Modbus Gateway Firmware<r02
Kunbus PR100088 Modbus gateway
Event History
Feb 12, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-6549.
2
What is the severity of CVE-2019-6549?
The severity of CVE-2019-6549 is high with a CVSS score of 7.2.
3
How can an attacker exploit CVE-2019-6549?
An attacker can exploit CVE-2019-6549 by retrieving plain-text credentials stored in an XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
4
Is Kunbus PR100088 Modbus gateway vulnerable to CVE-2019-6549?
No, Kunbus PR100088 Modbus gateway is not vulnerable to CVE-2019-6549.
5
How can I fix CVE-2019-6549?
To fix CVE-2019-6549, update to Release R02 (or Software Version 1.1.13166) of the PR100088 Modbus gateway firmware.