CVE-2019-6808: Critical severity modicon premium firmware vulnerability
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6808?
CVE-2019-6808 is a vulnerability that exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium, which could cause remote code execution by overwriting configuration settings of the controller over Modbus.
How severe is CVE-2019-6808?
CVE-2019-6808 has a severity rating of 9.8 on a scale of 1 to 10.
Which software versions are affected by CVE-2019-6808?
All versions of Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2019-6808.
How can CVE-2019-6808 be fixed?
To fix CVE-2019-6808, it is recommended to update to the latest version of the affected software.
Where can I find more information about CVE-2019-6808?
More information about CVE-2019-6808 can be found at the following references: [Reference 1](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) and [Reference 2](https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0771).