Improper Check for Unusual or Exceptional Conditions in Schneider Electric products - CVE-2019-6833
Published: February 14, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the HMI may temporarily freeze when the device receives a high rate of frames. When the attack stops, the buffered commands are processed by the HMI. A remote attacker can cause a denial of service condition on the target system.
Affected software
Magelis HMISTO
Magelis XBTGH
Magelis HMIGTU
Magelis HMIGTUX
Magelis HMISCU
Magelis HMISTU
Magelis XBTGT
Magelis XBTGC
Magelis HMIGXO
Magelis HMIGXU