CVE-2019-6845: High severity schneider electric modicon m580 firmware vulnerability
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-6845.
What is the severity level of CVE-2019-6845?
CVE-2019-6845 has a severity level of 7.5 (high).
What is the affected software for CVE-2019-6845?
The affected software for CVE-2019-6845 includes Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum (all firmware versions).
How can this vulnerability be exploited?
This vulnerability can be exploited by transferring applications to the controller using the Modbus TCP protocol.
How can I fix CVE-2019-6845?
To fix CVE-2019-6845, apply the necessary patch or firmware update provided by Schneider Electric.