Schneider Electric Se Modicon M580 vulnerabilities

4 known vulnerabilities affecting schneider_electric_se/modicon_m580.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2019-6828HIGHCVSS 7.5vfirmware version prior to V2.902019-09-17
CVE-2019-6828 [HIGH] CWE-248 CVE-2019-6828: A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), M A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.
cvelistv5nvd
CVE-2019-6829HIGHCVSS 7.5vfirmware version prior to V2.902019-09-17
CVE-2019-6829 [HIGH] CWE-248 CVE-2019-6829: A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.
cvelistv5nvd
CVE-2019-6809HIGHCVSS 7.5vfirmware version prior to V2.902019-09-17
CVE-2019-6809 [HIGH] CWE-248 CVE-2019-6809: A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90 A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (firmware versions prior to V3.10), Modicon Premium (all versions), Modicon Quantum (all versions), which could cause a possible denial of service when reading invalid data from the controller.
cvelistv5nvd
CVE-2019-6830MEDIUMCVSS 5.9vall versions prior to V2.802019-09-17
CVE-2019-6830 [MEDIUM] CWE-248 CVE-2019-6830: A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, whic A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
cvelistv5nvd