CVE-2019-6806

6 documents5 sources
Severity
7.5HIGH
EPSS
0.4%
top 37.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateMay 24

Description

A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5modicon_m580_modicon_m340_modicon_quantum_modicon_premiumModicon M580 Modicon M340 Modicon Quantum Modicon Premium

🔴Vulnerability Details

4
GHSA
GHSA-94xj-j76p-7vh3: A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which cou2022-05-24
OSV
thunderbird vulnerabilities2020-04-21
OSV
firefox vulnerabilities2020-03-11
CVEList
CVE-2019-6806: A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which cou2019-05-22

💥Exploits & PoCs

1
Exploit-DB
The Company Business Website CMS - Multiple Vulnerabilities2019-03-21
CVE-2019-6806 (HIGH CVSS 7.5) | A CWE-200: Information Exposure vul | cvebase.io