First published: Tue Oct 29 2019(Updated: )
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M580 Firmware | ||
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 | ||
schneider-electric tsxmcpc002m | ||
schneider-electric tsxmcpc002m firmware | ||
schneider-electric tsxmcpc512k | ||
Schneider Electric TSXMCPC512K Firmware | ||
Schneider Electric TSX MFPP 001 M | ||
schneider-electric tsxmfpp001m firmware | ||
Schneider Electric TSXMFPP002M | ||
Schneider Electric TSXMFPP002M | ||
Schneider Electric TSXMFPP004M Firmware | ||
Schneider Electric TSXMFPP004M Firmware | ||
Schneider Electric TSXMFPP512K Firmware | ||
tsxmfpp512k | ||
schneider-electric tsxmrpc001m | ||
schneider-electric tsxmrpc001m firmware | ||
Schneider Electric TSXMRPC002M Firmware | ||
Schneider Electric TSXMRPC002M Firmware | ||
Schneider Electric TSXMRP Series | ||
schneider-electric tsxmrpc003m firmware | ||
Schneider Electric TSXMRPC007M Firmware | ||
Schneider Electric TSXMRPC007M Firmware | ||
schneider-electric tsxmrpc01m7 firmware | ||
Schneider Electric TSX MR Series | ||
Schneider Electric TSXMRPC768K Firmware | ||
Schneider Electric TSXMRPC768K Firmware | ||
schneider-electric tsxmrpf004m firmware | ||
schneider-electric tsxmrpf004m | ||
Schneider Electric TSXMRPF008M | ||
schneider-electric tsxmrpf008m firmware | ||
schneider-electric tsxmfp0128p2 | ||
schneider-electric tsxmfp0128p2 firmware | ||
Schneider Electric TSX MFP 064 P2 Firmware | ||
Schneider Electric TSX MFP 064 P2 Firmware | ||
Schneider Electric TSXMFPP224K | ||
Schneider Electric TSXMFPP224K | ||
Schneider Electric TSXMFPP384K Firmware | ||
Schneider Electric TSXMFPP384K Firmware | ||
schneider-electric tsxmrpc448k firmware | ||
schneider-electric tsxmrpc448k | ||
Schneider Electric TSXMRPP224K | ||
schneider-electric tsxmrpp224k firmware | ||
Schneider Electric TSXMRPP384K | ||
Schneider Electric TSXMRPP384K |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-6845.
CVE-2019-6845 has a severity level of 7.5 (high).
The affected software for CVE-2019-6845 includes Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum (all firmware versions).
This vulnerability can be exploited by transferring applications to the controller using the Modbus TCP protocol.
To fix CVE-2019-6845, apply the necessary patch or firmware update provided by Schneider Electric.