CVE-2019-6849: Infoleak
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this information exposure vulnerability?
The vulnerability ID of this information exposure vulnerability is CVE-2019-6849.
What is the severity rating of CVE-2019-6849?
The severity rating of CVE-2019-6849 is high, with a score of 7.5.
Which software is affected by CVE-2019-6849?
The software affected by CVE-2019-6849 includes Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321.
How can the vulnerability be exploited?
The vulnerability can be exploited by using specific Modbus services provided by the REST API of the affected controller/communication module.
Is there a fix available for CVE-2019-6849?
To mitigate this vulnerability, it is recommended to apply the patches provided by Schneider-electric. Please refer to the vendor's website for more information.