First published: Wed May 22 2019(Updated: )
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon Premium | <=3.20 | |
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | <=3.60 | |
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon M340 Firmware | <3.10 | |
Schneider Electric Modicon M340 | ||
Schneider Electric Modicon M580 Firmware | <2.90 | |
Schneider Electric Modicon M580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6808 is a vulnerability that exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium, which could cause remote code execution by overwriting configuration settings of the controller over Modbus.
CVE-2019-6808 has a severity rating of 9.8 on a scale of 1 to 10.
All versions of Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2019-6808.
To fix CVE-2019-6808, it is recommended to update to the latest version of the affected software.
More information about CVE-2019-6808 can be found at the following references: [Reference 1](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) and [Reference 2](https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0771).