cbcvebase.
CVE-2019-6808
published 2019-05-22

CVE-2019-6808: A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.

Affected

6 ranges
VendorProductVersion rangeFixed in
mozillafirefox>= 0 < 74.0+build3-0ubuntu0.16.04.174.0+build3-0ubuntu0.16.04.1
mozillafirefox>= 0 < 74.0+build3-0ubuntu0.18.04.174.0+build3-0ubuntu0.18.04.1
schneider-electricmodicon_m340_firmware< 3.103.10
schneider-electricmodicon_m580_firmware< 2.902.90
schneider-electricmodicon_premium_firmware<= 3.20
schneider-electricmodicon_quantum_firmware<= 3.60

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv6.5MEDIUM