CVE-2019-6829: High severity Schneider-electric Modicon M580 Firmware vulnerability
Published Sep 17, 2019
·Updated
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.
Affected Software
8 affected components
Schneider-electric Modicon M580 Firmware<2.90
Schneider-electric Modicon M580
Schneider-electric Modicon M340 Firmware<3.10
Schneider-electric Modicon M340
All of the following
Schneider-electric Modicon M580 Firmware<2.90
Schneider-electric Modicon M580
All of the following
Schneider-electric Modicon M340 Firmware<3.10
Schneider-electric Modicon M340
Event History
Sep 17, 2019
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-6829.
2
What is the severity of CVE-2019-6829?
The severity of CVE-2019-6829 is high with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2019-6829?
Modicon M580 firmware versions prior to V2.90, and Modicon M340 firmware versions prior to V3.10 are affected by CVE-2019-6829.
4
What is the impact of CVE-2019-6829?
CVE-2019-6829 could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.
5
Is there a fix available for CVE-2019-6829?
Yes, a fix is available. Please refer to the reference link for more information.