CVE-2019-6831: High severity schneider electric bmxnor0200h firmware vulnerability
Published Sep 17, 2019
·Updated
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause disconnection of active connections when an unusually high number of IEC 60870- 5-104 packets are received by the module on port 2404/TCP.
Affected Software
2 affected components
Schneider-electric Bmxnor0200h Firmware
Schneider-electric Bmxnor0200h
Event History
Sep 17, 2019
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-6831.
2
What is the severity rating of CVE-2019-6831?
CVE-2019-6831 has a severity rating of 8.6 (High).
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-754.
4
Which software is affected by CVE-2019-6831?
BMXNOR0200H Ethernet / Serial RTU module (all firmware versions) by Schneider Electric is affected by CVE-2019-6831.
5
How can CVE-2019-6831 be exploited?
CVE-2019-6831 can be exploited by sending an unusually high number of IEC 60870-5-104 packets to the BMXNOR0200H module on port.