CVE-2019-6855: High severity ecostruxure control expert vulnerability
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6855?
CVE-2019-6855 is an Incorrect Authorization vulnerability that exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10).
How severe is CVE-2019-6855?
CVE-2019-6855 has a severity rating of 7.3 (High).
What software is affected by CVE-2019-6855?
The software affected by CVE-2019-6855 includes EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10).
How can I fix CVE-2019-6855?
To fix CVE-2019-6855, it is recommended to update the affected software to the latest version.
Where can I find more information about CVE-2019-6855?
You can find more information about CVE-2019-6855 at the following link: [CVE-2019-6855](https://www.se.com/ww/en/download/document/SEVD-2019-344-02/).