CVE-2019-6808
published 2019-05-22CVE-2019-6808: A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | >= 0 < 74.0+build3-0ubuntu0.16.04.1 | 74.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 74.0+build3-0ubuntu0.18.04.1 | 74.0+build3-0ubuntu0.18.04.1 |
| schneider-electric | modicon_m340_firmware | < 3.10 | 3.10 |
| schneider-electric | modicon_m580_firmware | < 2.90 | 2.90 |
| schneider-electric | modicon_premium_firmware | <= 3.20 | — |
| schneider-electric | modicon_quantum_firmware | <= 3.60 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.5MEDIUM