Schneider Electric Se Modicon Quantum vulnerabilities

3 known vulnerabilities affecting schneider_electric_se/modicon_quantum.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3

Vulnerabilities

Page 1 of 1
CVE-2019-6828HIGHCVSS 7.5vall versions2019-09-17
CVE-2019-6828 [HIGH] CWE-248 CVE-2019-6828: A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), M A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.
cvelistv5nvd
CVE-2019-6809HIGHCVSS 7.5vall versions2019-09-17
CVE-2019-6809 [HIGH] CWE-248 CVE-2019-6809: A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90 A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (firmware versions prior to V3.10), Modicon Premium (all versions), Modicon Quantum (all versions), which could cause a possible denial of service when reading invalid data from the controller.
cvelistv5nvd
CVE-2018-7240HIGHCVSS 8.8vAll versions of Modicon Quantum communication modules2018-04-18
CVE-2018-7240 [HIGH] CWE-787 CVE-2018-7240: A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
cvelistv5nvd