CVE-2023-25619: High severity schneider electric modicon m580 firmware vulnerability
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25619?
CVE-2023-25619 is a CWE-754 vulnerability that could cause denial of service of the controller when communicating over the Modbus TCP protocol.
What software is affected by CVE-2023-25619?
Schneider-electric Modicon M580 Firmware versions up to 4.10 and Schneider-electric Modicon M340 Firmware versions up to 3.51 are affected.
What is the severity of CVE-2023-25619?
CVE-2023-25619 has a severity rating of 7.5 (High).
How can I fix CVE-2023-25619?
To fix CVE-2023-25619, it is recommended to apply the patches or firmware updates provided by Schneider-electric.
Where can I find more information about CVE-2023-25619?
More information about CVE-2023-25619 can be found in the security and safety notice document provided by Schneider-electric at: https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-05.pdf