#VU21518 Code Injection in Modicon Quantum - CVE-2019-6816

 

#VU21518 Code Injection in Modicon Quantum - CVE-2019-6816

Published: October 3, 2019


Vulnerability identifier: #VU21518
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-6816
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Modicon Quantum
Software vendor:
Schneider Electric

Description

The vulnerability allows a remote attacker to cause the firmware modification.

The vulnerability exists due to improper input validation. A remote attacker can cause an unauthorized firmware modification with possible denial of service (DoS) condition when using Modbus protocol.



Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links