First published: Tue Oct 29 2019(Updated: )
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon Bmenoc 0311 Firmware | ||
Schneider-electric Modicon Bmenoc 0311 | ||
Schneider-electric Modicon Bmenoc 0321 Firmware | ||
Schneider-electric Modicon Bmenoc 0321 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this information exposure vulnerability is CVE-2019-6850.
The severity level of CVE-2019-6850 is high with a severity value of 7.5.
CVE-2019-6850 affects Modicon M580 Firmware, Modicon BMENOC 0311 Firmware, and Modicon BMENOC 0321 Firmware.
CVE-2019-6850 can cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.
Please refer to the Schneider Electric website for information on available fixes or patches for CVE-2019-6850.