First published: Tue Oct 29 2019(Updated: )
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Tsxmcpc002m Firmware | ||
Schneider-electric Tsxmcpc002m | ||
Schneider-electric Tsxmcpc512k Firmware | ||
Schneider-electric Tsxmcpc512k | ||
Schneider-electric Tsxmfpp001m Firmware | ||
Schneider-electric Tsxmfpp001m | ||
Schneider-electric Tsxmfpp002m Firmware | ||
Schneider-electric Tsxmfpp002m | ||
Schneider-electric Tsxmfpp004m Firmware | ||
Schneider-electric Tsxmfpp004m | ||
Schneider-electric Tsxmfpp512k Firmware | ||
Schneider-electric Tsxmfpp512k | ||
Schneider-electric Tsxmrpc001m Firmware | ||
Schneider-electric Tsxmrpc001m | ||
Schneider-electric Tsxmrpc002m Firmware | ||
Schneider-electric Tsxmrpc002m | ||
Schneider-electric Tsxmrpc003m Firmware | ||
Schneider-electric Tsxmrpc003m | ||
Schneider-electric Tsxmrpc007m Firmware | ||
Schneider-electric Tsxmrpc007m | ||
Schneider-electric Tsxmrpc01m7 Firmware | ||
Schneider-electric Tsxmrpc01m7 | ||
Schneider-electric Tsxmrpc768k Firmware | ||
Schneider-electric Tsxmrpc768k | ||
Schneider-electric Tsxmrpf004m Firmware | ||
Schneider-electric Tsxmrpf004m | ||
Schneider-electric Tsxmrpf008m Firmware | ||
Schneider-electric Tsxmrpf008m | ||
Schneider-electric Tsxmfp0128p2 Firmware | ||
Schneider-electric Tsxmfp0128p2 | ||
Schneider-electric Tsxmfp064p2 Firmware | ||
Schneider-electric Tsxmfp064p2 | ||
Schneider-electric Tsxmfpp224k Firmware | ||
Schneider-electric Tsxmfpp224k | ||
Schneider-electric Tsxmfpp384k Firmware | ||
Schneider-electric Tsxmfpp384k | ||
Schneider-electric Tsxmrpc448k Firmware | ||
Schneider-electric Tsxmrpc448k | ||
Schneider-electric Tsxmrpp224k Firmware | ||
Schneider-electric Tsxmrpp224k | ||
Schneider-electric Tsxmrpp384k Firmware | ||
Schneider-electric Tsxmrpp384k |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2019-6851.
CVE-2019-6851 has a severity rating of 7.5 (high).
Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum (all firmware versions) are affected by CVE-2019-6851.
CVE-2019-6851 causes information disclosure from the controller when using the TFTP protocol.
There is no known fix for CVE-2019-6851 at this time, consider applying security controls to mitigate the risk.