First published: Tue Oct 29 2019(Updated: )
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the controller with an empty firmware package using FTP protocol.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Bmxcra Firmware | ||
Schneider-electric Modicon Bmxcra | ||
Schneider-electric Modicon 140cra Firmware | ||
Schneider-electric Modicon 140cra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Modicon M580 vulnerability is CVE-2019-6843.
The severity of CVE-2019-6843 is medium, with a severity value of 4.9.
CVE-2019-6843 affects Modicon M580 with firmware versions prior to V3.10, Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions).
The CWE ID for this vulnerability is CWE-755: Improper Handling of Exceptional Conditions.
This vulnerability could be exploited to cause a Denial of Service attack on the PLC when upgrading the firmware.