First published: Mon Jan 06 2020(Updated: )
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Control Expert | <14.1 | |
Schneider-electric Ecostruxure Control Expert | =14.1 | |
Schneider-electric Unity Pro | ||
Schneider-electric Modicon M580 Bmep584040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep584040 | ||
Schneider-electric Modicon M580 Bmeh584040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmeh584040 | ||
Schneider-electric Modicon M580 Bmep586040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep586040 | ||
Schneider-electric Modicon M580 Bmeh586040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmeh586040 | ||
Schneider-electric Modicon M580 Bmep581020 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep581020 | ||
Schneider-electric Modicon M580 Bmep582020 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep582020 | ||
Schneider-electric Modicon M580 Bmep582040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep582040 | ||
Schneider-electric Modicon M580 Bmep583020 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep583020 | ||
Schneider-electric Modicon M580 Bmep583040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep583040 | ||
Schneider-electric Modicon M580 Bmep584020 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep584020 | ||
Schneider-electric Modicon M580 Bmep585040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep585040 | ||
Schneider-electric Modicon M580 Bmeh582040 Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmeh582040 | ||
Schneider-electric Modicon M580 Bmep584040s Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep584040s | ||
Schneider-electric Modicon M580 Bmeh584040s Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmeh584040s | ||
Schneider-electric Modicon M580 Bmeh586040s Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmeh586040s | ||
Schneider-electric Modicon M580 Bmep582040s Firmware | <3.10 | |
Schneider-electric Modicon M580 Bmep582040s | ||
Schneider-electric Modicon M340 Bmxp3420302 Firmware | <3.20 | |
Schneider-electric Modicon M340 Bmxp3420302 | ||
Schneider-electric Modicon M340 Bmxp342020 Firmware | <3.20 | |
Schneider-electric Modicon M340 Bmxp342020 | ||
Schneider-electric Modicon M340 Bmxp342000 Firmware | <3.20 | |
Schneider-electric Modicon M340 Bmxp342000 | ||
Schneider-electric Modicon M340 Bmxp341000 Firmware | <3.20 | |
Schneider-electric Modicon M340 Bmxp341000 | ||
Schneider-electric Modicon M340 Bmxp3420102 Firmware | <3.20 | |
Schneider-electric Modicon M340 Bmxp3420102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6855 is an Incorrect Authorization vulnerability that exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10).
CVE-2019-6855 has a severity rating of 7.3 (High).
The software affected by CVE-2019-6855 includes EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10).
To fix CVE-2019-6855, it is recommended to update the affected software to the latest version.
You can find more information about CVE-2019-6855 at the following link: [CVE-2019-6855](https://www.se.com/ww/en/download/document/SEVD-2019-344-02/).