First published: Tue Oct 29 2019(Updated: )
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with no firmware image inside the package using FTP protocol.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Bmxcra Firmware | ||
Schneider-electric Modicon Bmxcra | ||
Schneider-electric Modicon 140cra Firmware | ||
Schneider-electric Modicon 140cra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-6841.
The severity of CVE-2019-6841 is medium with a severity value of 4.9.
Modicon M580 with firmware versions prior to V3.10, Modicon M340 (all versions), and Modicon BMxCRA and 140CRA modules (all versions) are affected.
CVE-2019-6841 can be exploited to cause a Denial of Service attack on the affected PLC when upgrading firmware.
More information about CVE-2019-6841 can be found at: https://www.se.com/ww/en/download/document/SEVD-2019-281-02/