Improper access control in Schneider Electric products - CVE-2019-6808
Published: October 3, 2019
Vulnerability identifier: #VU21494
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6808
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can overwrite configuration settings of the controller over Modbus and execute arbitrary code on the target system.
Affected software
Modicon Quantum
Modicon Premium
Modicon M340
Modicon M580
Modicon Premium
Modicon M340
Modicon M580
How to mitigate CVE-2019-6808
Install updates from vendor's website.
Modicon M340 - update to 3.10
Modicon M580 - update to 2.90
Modicon M580 - update to 2.90