CVE-2019-6848: High severity schneider electric modicon m580 firmware vulnerability
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2019-6848.
What is the severity rating of CVE-2019-6848?
The severity rating of CVE-2019-6848 is high (8.6).
What is the affected software for CVE-2019-6848?
The affected software for CVE-2019-6848 includes Schneider-electric Modicon M580 Firmware and Schneider-electric Modicon Bmenoc 0311 and 0321 Firmware.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-755.
How can I fix CVE-2019-6848?
To fix CVE-2019-6848, it is recommended to apply the necessary patches or updates provided by Schneider Electric.