CVE-2019-6812: High severity schneider electric bmxnor0200h firmware vulnerability
Published May 22, 2019
·Updated
A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confidentiality issue when using FTP protocol.
Affected Software
3 affected components
Schneider-electric Bmx-nor-0200h Firmware=1.7-ir17
Schneider-electric Bmx-nor-0200h Firmware=1.7-ir18
Schneider-electric Bmx-nor-0200h
Event History
May 22, 2019
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6812?
CVE-2019-6812 is classified as a confidentiality issue due to the use of hardcoded credentials.
2
How do I fix CVE-2019-6812?
To fix CVE-2019-6812, upgrade the firmware of the Schneider Electric BMX-NOR-0200H to version 1.7 IR 19 or later.
3
What systems are affected by CVE-2019-6812?
CVE-2019-6812 affects Schneider Electric BMX-NOR-0200H firmware versions 1.7 IR 17 and 1.7 IR 18.
4
What potential risks does CVE-2019-6812 pose?
CVE-2019-6812 can lead to unauthorized access due to hardcoded credentials, increasing the risk of data breaches.
5
Is a workaround available for CVE-2019-6812?
There are no known workarounds for CVE-2019-6812; applying the firmware update is the recommended solution.