First published: Tue Oct 29 2019(Updated: )
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon Bmenoc 0311 Firmware | ||
Schneider-electric Modicon Bmenoc 0311 | ||
Schneider-electric Modicon Bmenoc 0321 Firmware | ||
Schneider-electric Modicon Bmenoc 0321 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this information exposure vulnerability is CVE-2019-6849.
The severity rating of CVE-2019-6849 is high, with a score of 7.5.
The software affected by CVE-2019-6849 includes Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321.
The vulnerability can be exploited by using specific Modbus services provided by the REST API of the affected controller/communication module.
To mitigate this vulnerability, it is recommended to apply the patches provided by Schneider-electric. Please refer to the vendor's website for more information.