First published: Wed May 22 2019(Updated: )
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon Premium Firmware | ||
Schneider-electric Modicon Premium | ||
Schneider-electric Modicon Quantum Firmware | ||
Schneider-electric Modicon Quantum | ||
Schneider-electric Modicon M340 Firmware | <3.10 | |
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon M580 Firmware | <2.90 | |
Schneider-electric Modicon M580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6806 is a CWE-200: Information Exposure vulnerability that exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium devices.
CVE-2019-6806 affects all versions of Schneider-electric Modicon Premium firmware.
CVE-2019-6806 affects all versions of Schneider-electric Modicon Quantum firmware.
CVE-2019-6806 affects Schneider-electric Modicon M340 firmware up to version 3.10.
CVE-2019-6806 affects Schneider-electric Modicon M580 firmware up to version 2.90.
CVE-2019-6806 has a severity rating of 7.5 (High).
You can find more information about CVE-2019-6806 at the following references: [Schneider-Electric Advisory](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) and [Talos Intelligence](https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0769).