First published: Tue Sep 17 2019(Updated: )
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (firmware versions prior to V3.10), Modicon Premium (all versions), Modicon Quantum (all versions), which could cause a possible denial of service when reading invalid data from the controller.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M580 Firmware | <2.90 | |
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M340 Firmware | <3.10 | |
Schneider Electric Modicon M340 | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-6809 is high with a severity value of 7.5.
Modicon M580 firmware versions prior to V2.90, Modicon M340 firmware versions prior to V3.10, Modicon Premium (all versions), and Modicon Quantum (all versions) are affected by CVE-2019-6809.
CVE-2019-6809 is a CWE-248: Uncaught Exception vulnerability.
The vulnerability CVE-2019-6809 can be exploited by reading invalid data from the affected software, potentially causing a denial of service.
You can find more information about CVE-2019-6809 at the following link: [CVE-2019-6809](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/)