First published: Wed May 22 2019(Updated: )
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the products: Modicon M340 - firmware versions prior to V3.01, Modicon M580 - firmware versions prior to V2.80, All firmware versions of Modicon Quantum and Modicon Premium.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider Electric Modicon M340 Firmware | <3.01 | |
Any of | ||
Schneider Electric Modicon M340 BMXP341000 | ||
Schneider Electric Modicon M340 BMXP341000H | ||
Schneider Electric Modicon M340 BMXP342000 Firmware | ||
Schneider Electric Modicon M340 BMXP3420102 | ||
Schneider Electric Modicon M340 BMXP3420102CL Firmware | ||
Schneider Electric Modicon M340 BMXP342020 | ||
Schneider Electric Modicon M340 BMXP342020H | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
Schneider Electric Modicon M340 BMXP3420302CL | ||
Schneider Electric Modicon M340 BMXP3420302H Firmware | ||
All of | ||
Schneider Electric Modicon M580 Firmware | <2.80 | |
Any of | ||
Schneider Electric BMEH582040 Firmware | ||
Schneider Electric BMEH582040C | ||
Schneider Electric BMEH584040 | ||
Schneider Electric BMEH584040C | ||
Schneider Electric BMEH586040 | ||
schneider-electric bmeh586040c | ||
Schneider Electric Modicon M580 BMEP581020 | ||
schneider-electric Modicon M580 BMEP581020H firmware | ||
Modicon M580 | ||
Modicon M580 | ||
schneider-electric Modicon M580 | ||
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040S | ||
Schneider Electric Modicon M580 BMEP583020 | ||
Schneider Electric Modicon M580 BMEP583040 | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric modicon m580 bmep586040 firmware | ||
schneider-electric Modicon M580 bmep586040c firmware | ||
All of | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
All of | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon M340 Firmware | <3.01 | |
Schneider Electric BMXP341000 Firmware | ||
Schneider Electric BMXP341000H Firmware | ||
Schneider Electric BMXP342000 Firmware | ||
Schneider Electric BMXP3420102 Firmware | ||
Schneider Electric BMXP3420102CL | ||
schneider-electric BMXP342020H firmware | ||
schneider-electric BMXP342020H firmware | ||
Schneider Electric BMXP3420302H firmware | ||
Schneider Electric BMXP3420302CL Firmware | ||
Schneider Electric BMXP3420302H firmware | ||
Schneider Electric Modicon M580 Firmware | <2.80 | |
Schneider Electric BMEH582040 Firmware | ||
Schneider Electric BMEH582040C | ||
Schneider Electric BMEH584040 | ||
Schneider Electric BMEH584040C | ||
Schneider Electric BMEH586040 | ||
schneider-electric bmeh586040c | ||
Schneider Electric Modicon M580 BMEP581020 | ||
schneider-electric Modicon M580 BMEP581020H firmware | ||
Modicon M580 | ||
Modicon M580 | ||
schneider-electric Modicon M580 | ||
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040S | ||
Schneider Electric Modicon M580 BMEP583020 | ||
Schneider Electric Modicon M580 BMEP583040 | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric modicon m580 bmep586040 firmware | ||
schneider-electric Modicon M580 bmep586040c firmware | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2019-6819.
CVE-2019-6819 has a severity rating of 7.5, which is considered high.
CVE-2019-6819 affects the following products: Modicon M340 firmware versions prior to V3.01, Modicon M580 firmware versions prior to V2.80.
CVE-2019-6819 can be exploited by sending specific Modbus frames to the affected controller.
Yes, a fix is available for CVE-2019-6819. It is recommended to update the firmware to version V3.01 for Modicon M340 and V2.80 for Modicon M580.