First published: Tue Oct 29 2019(Updated: )
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon Bmenoc 0311 Firmware | ||
Schneider-electric Modicon Bmenoc 0311 | ||
Schneider-electric Modicon Bmenoc 0321 Firmware | ||
Schneider-electric Modicon Bmenoc 0321 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this advisory is CVE-2019-6848.
The severity rating of CVE-2019-6848 is high (8.6).
The affected software for CVE-2019-6848 includes Schneider-electric Modicon M580 Firmware and Schneider-electric Modicon Bmenoc 0311 and 0321 Firmware.
The CWE ID for this vulnerability is CWE-755.
To fix CVE-2019-6848, it is recommended to apply the necessary patches or updates provided by Schneider Electric.