CVE-2019-6844: Medium severity schneider electric modicon m580 firmware vulnerability
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC when upgrading the controller with a firmware package containing an invalid web server image using FTP protocol.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-6844.
What is the severity level of CVE-2019-6844?
The severity level of CVE-2019-6844 is medium.
Which software is affected by CVE-2019-6844?
The Modicon M580, Modicon M340, Modicon BMxCRA, and 140CRA modules are affected by CVE-2019-6844.
What is the impact of CVE-2019-6844?
CVE-2019-6844 could cause a Denial of Service attack on the PLC when upgrading the controller with a firmware package containing an invalid web.
Is there a fix available for CVE-2019-6844?
To fix CVE-2019-6844, it is recommended to update the firmware to a version that addresses the vulnerability.