CVE-2019-6811: High severity schneider electric modicon quantum firmware vulnerability
An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6811?
CVE-2019-6811 is an Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability that exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier.
What is the severity of CVE-2019-6811?
The severity of CVE-2019-6811 is high with a severity value of 7.5.
Which software versions are affected by CVE-2019-6811?
Modicon Quantum 140 NOE771x1 version 6.9 and earlier are affected by CVE-2019-6811.
How can CVE-2019-6811 be exploited?
CVE-2019-6811 can be exploited by sending an IP fragmented packet with a length greater than 65535 bytes to the module.
Is there a fix for CVE-2019-6811?
Yes, an update to Modicon Quantum 140 NOE771x1 firmware to a version that is later than 6.9 is available to fix CVE-2019-6811.