CVE-2019-6847: Medium severity schneider electric modicon m580 firmware vulnerability
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FTP service when upgrading the firmware with a version incompatible with the application in the controller using FTP protocol.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6847?
CVE-2019-6847 is a vulnerability that exists in Modicon M580, Modicon M340, Modicon BMxCRA, and 140CRA modules, which could cause a Denial of Service attack on the FTP service when upgrading the firmware with a version incompatible with the application.
What is the severity of CVE-2019-6847?
The severity of CVE-2019-6847 is medium with a CVSS score of 4.9.
Which software is affected by CVE-2019-6847?
Modicon M580, Modicon M340, Modicon BMxCRA, and 140CRA modules are affected by CVE-2019-6847.
How can CVE-2019-6847 be exploited?
CVE-2019-6847 can be exploited by upgrading the firmware with a version incompatible with the application, causing a Denial of Service attack on the FTP service.
How can I fix CVE-2019-6847?
To fix CVE-2019-6847, it is recommended to update the firmware to a compatible version that addresses the vulnerability.