First published: Mon Jan 06 2020(Updated: )
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
EcoStruxure Control Expert | <14.1 | |
EcoStruxure Control Expert | =14.1 | |
Unity Pro | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | <3.10 | |
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
Schneider Electric Modicon M580 BMEH584040 Firmware | <3.10 | |
schneider-electric Modicon M580 bmeh584040c | ||
schneider-electric Modicon M580 bmep586040c firmware | <3.10 | |
schneider-electric modicon m580 bmep586040 firmware | ||
Schneider Electric Modicon M580 | <3.10 | |
Schneider Electric Modicon M580 | ||
Modicon M580 | <3.10 | |
Schneider Electric Modicon M580 BMEP581020 | ||
Schneider Electric Modicon M580 BMEP582020 Firmware | <3.10 | |
Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <3.10 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP583020 Firmware | <3.10 | |
Schneider Electric Modicon M580 BMEP583020 | ||
Schneider Electric Modicon M580 BMEP583040 Firmware | <3.10 | |
Schneider Electric Modicon M580 BMEP583040 | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | <3.10 | |
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | <3.10 | |
schneider-electric Modicon M580 BMEP585040C Firmware | ||
Schneider Electric Modicon M580 BMEH582040 Firmware | <3.10 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | <3.10 | |
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
Schneider Electric Modicon M580 BMEH584040S Firmware | <3.10 | |
Schneider Electric Modicon M580 BMEH584040S Firmware | ||
Schneider Electric Modicon M580 Firmware | <3.10 | |
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <3.10 | |
Schneider Electric Modicon M580 BMEP582040S | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | <3.20 | |
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
Schneider Electric Modicon M340 BMXP342020 Firmware | <3.20 | |
Schneider Electric Modicon M340 BMXP342020 | ||
Schneider Electric Modicon M340 BMXP342000 Firmware | <3.20 | |
Schneider Electric Modicon M340 BMXP342000 Firmware | ||
Schneider Electric Modicon M340 BMXP341000 Firmware | <3.20 | |
Schneider Electric Modicon M340 BMXP341000 | ||
Schneider Electric Modicon M340 BMXP3420102 Firmware | <3.20 | |
Schneider Electric Modicon M340 BMXP3420102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6855 is an Incorrect Authorization vulnerability that exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10).
CVE-2019-6855 has a severity rating of 7.3 (High).
The software affected by CVE-2019-6855 includes EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10).
To fix CVE-2019-6855, it is recommended to update the affected software to the latest version.
You can find more information about CVE-2019-6855 at the following link: [CVE-2019-6855](https://www.se.com/ww/en/download/document/SEVD-2019-344-02/).