CVE-2019-6808
published 2019-05-22CVE-2019-6808: A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could…
PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.16%
94.2th percentile
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | >= 0 < 74.0+build3-0ubuntu0.16.04.1 | 74.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 74.0+build3-0ubuntu0.18.04.1 | 74.0+build3-0ubuntu0.18.04.1 |
| schneider-electric | modicon_m340_firmware | < 3.10 | 3.10 |
| schneider-electric | modicon_m580_firmware | < 2.90 | 2.90 |
| schneider-electric | modicon_premium_firmware | <= 3.20 | — |
| schneider-electric | modicon_quantum_firmware | <= 3.60 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gcj2-7vc3-x83p: A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which
ghsa_unreviewed·2022-05-24
CVE-2019-6808 [CRITICAL] CWE-306 GHSA-gcj2-7vc3-x83p: A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
OSV
firefox vulnerabilities
osv·2020-03-11·CVSS 6.5
CVE-2019-20503 firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the URL or
other browser chrome, obtain sensitive information, bypass Content
Security Policy (CSP) protections, or execute arbitrary code.
(CVE-2019-20503, CVE-2020-6805, CVE-2020-6806, CVE-2020-6807,
CVE-2020-6808, CVE-2020-6810, CVE-2020-6812, CVE-2020-6813, CVE-2020-6814,
CVE-2020-6815)
It was discovered that Web Extensions with the all-url permission could
access local files. If a user were tricked in to installing a specially
crafted extension, an attacker could potentially exploit this to obtain
sensitive information. (CVE-2020-6809)
It was discovered that the
CISA ICS
Schneider Electric Modicon Controllers
cisa_ics·2025-04-24·CVSS 9.8
[CRITICAL] Schneider Electric Modicon Controllers
ICS Advisory
##
Schneider Electric Modicon Controllers
Release DateApril 24, 2025
Alert CodeICSA-25-114-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum
- Vulnerabilities: Trust Boundary Violation, Uncaught Exception, Exposure of Sensitive Information to an Unauthorized Actor, Authentication Bypass by Spoofing, Improper Access Control, Reliance on Untrusted Inputs in a Security Decision, Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may risk execution of unsolici
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Schneider Electric Modicon M580
blogs_talos·2019-06-10·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in Schneider Electric Modicon M580
## Vulnerability Spotlight: Multiple vulnerabilities in Schneider Electric Modicon M580
Jared Rittle of Cisco Talos discovered these vulnerabilities.
## Executive summary
There are several vulnerabilities in the Schneider Electric Modicon M580 that could lead to a variety of conditions, including denial of service and the disclosure of sensitive information. The Modicon M580 is the latest in Schneider Electric's Modicon line of programmable automation controllers. The majority of the bugs we will discuss exist in UMAS requests made while operating the hardware. In accordance with our coordinated disclosure policy, Cisco Talos worked with Schneider Electric to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details
Schneide
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Schneider Electric Modicon M580
blogs_talos·2019-06-10·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in Schneider Electric Modicon M580
Jared Rittle of Cisco Talos discovered these vulnerabilities.
### Executive summary
There are several vulnerabilities in the Schneider Electric Modicon M580 that could lead to a variety of conditions, including denial of service and the disclosure of sensitive information. The Modicon M580 is the latest in Schneider Electric's Modicon line of programmable automation controllers. The majority of the bugs we will discuss exist in UMAS requests made while operating the hardware.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Schneider Electric to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability details
Schneider Electric Modicon M580 UMAS release reservation denial-of-service vulnerability (TALO
arXiv
The Global State of Security in Industrial Control Systems: An Empirical Analysis of Vulnerabilities around the World
arxiv_fulltext·2021-11-27
The Global State of Security in Industrial Control Systems: An Empirical Analysis of Vulnerabilities around the World
The Global State of Security in Industrial Control Systems: An Empirical Analysis of Vulnerabilities around the World
Simon Daniel Duque Anton,
Daniel Fraunholz,
Daniel Krohmer,
Daniel Reti,
Daniel Schneider,
and Hans Dieter Schotten
This is a pre-print of a paper published in the IEEE Internet of Things Journal.
Please cite as: SD Duque Anton, D Fraunholz, D Krohmer, D Reti, D Schneider, and HD Schotten: The Global State of Security in Industrial Control Systems: An Empirical Analysis of Vulnerabilites around the World, IEEE Internet of Things Journal, May 2021
S. D. Duque Anton was with the German Research Center for Artificial Intelligence. He is now with the comlet Verteilte Systeme GmbH and with the University of Kaiserslautern.
D. Reti, D. Schneider and H. D. Schotten are with the G
2019-05-22
Published