Improper Check for Unusual or Exceptional Conditions in Schneider Electric products - CVE-2019-6833

 

Improper Check for Unusual or Exceptional Conditions in Schneider Electric products - CVE-2019-6833

Published: February 14, 2020


Vulnerability identifier: #VU25342
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6833
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the HMI may temporarily freeze when the device receives a high rate of frames. When the attack stops, the buffered commands are processed by the HMI. A remote attacker can cause a denial of service condition on the target system.


Affected software

Magelis HMIGTO
Magelis HMISTO
Magelis XBTGH
Magelis HMIGTU
Magelis HMIGTUX
Magelis HMISCU
Magelis HMISTU
Magelis XBTGT
Magelis XBTGC
Magelis HMIGXO
Magelis HMIGXU

How to mitigate CVE-2019-6833

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins