Cleartext transmission of sensitive information in Schneider Electric products - CVE-2019-6845
Published: November 7, 2019
Vulnerability identifier: #VU22584
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6845
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel when transferring applications to the controller using Modbus TCP protocol. A remote attacker with ability to intercept network traffic can gain access to sensitive data.
Affected software
Modicon M340
Modicon M580
Modicon Premium
Modicon Quantum
Modicon M580
Modicon Premium
Modicon Quantum
How to mitigate CVE-2019-6845
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.