First published: Tue Sep 17 2019(Updated: )
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (firmware versions prior to V3.10), Modicon Premium (all versions), Modicon Quantum (all versions), which could cause a possible denial of service when reading invalid data from the controller.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | <2.90 | |
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | <3.10 | |
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Premium Firmware | ||
Schneider-electric Modicon Premium | ||
Schneider-electric Modicon Quantum Firmware | ||
Schneider-electric Modicon Quantum |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6809 is high with a severity value of 7.5.
Modicon M580 firmware versions prior to V2.90, Modicon M340 firmware versions prior to V3.10, Modicon Premium (all versions), and Modicon Quantum (all versions) are affected by CVE-2019-6809.
CVE-2019-6809 is a CWE-248: Uncaught Exception vulnerability.
The vulnerability CVE-2019-6809 can be exploited by reading invalid data from the affected software, potentially causing a denial of service.
You can find more information about CVE-2019-6809 at the following link: [CVE-2019-6809](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/)