First published: Tue Oct 29 2019(Updated: )
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC when upgrading the controller with a firmware package containing an invalid web server image using FTP protocol.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Bmxcra Firmware | ||
Schneider-electric Modicon Bmxcra | ||
Schneider-electric Modicon 140cra Firmware | ||
Schneider-electric Modicon 140cra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-6844.
The severity level of CVE-2019-6844 is medium.
The Modicon M580, Modicon M340, Modicon BMxCRA, and 140CRA modules are affected by CVE-2019-6844.
CVE-2019-6844 could cause a Denial of Service attack on the PLC when upgrading the controller with a firmware package containing an invalid web.
To fix CVE-2019-6844, it is recommended to update the firmware to a version that addresses the vulnerability.