CVE-2019-6842: Medium severity schneider electric modicon m580 firmware vulnerability
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with a missing web server image inside the package using FTP protocol.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-6842.
What is the severity level of CVE-2019-6842?
The severity level of CVE-2019-6842 is medium.
Which software is affected by this vulnerability?
The Modicon M580, Modicon M340, Modicon BMxCRA, and 140CRA modules (all firmware versions) are affected by this vulnerability.
What is the risk of this vulnerability?
This vulnerability could cause a Denial of Service attack on the PLC when upgrading the firmware with a missing web server image inside the package.
Is there a fix available for this vulnerability?
Please refer to the vendor's website for information on available fixes.