CVE-2019-6820: High severity Schneider-electric Modicon M100 Firmware vulnerability
A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-6820.
What is the severity rating for CVE-2019-6820?
CVE-2019-6820 has a severity rating of 8.2 (high).
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-306.
Which devices are affected by CVE-2019-6820?
Modicon M100, Modicon M200, Modicon M221, and ATV IMC Drive Controller are affected by CVE-2019-6820.
How can I fix CVE-2019-6820?
Please refer to the following link for information on how to fix CVE-2019-6820: [CVE-2019-6820 Fix](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-02/).