#VU21518 Code Injection in Modicon Quantum - CVE-2019-6816
Published: October 3, 2019
Vulnerability identifier: #VU21518
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-6816
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Modicon Quantum
Modicon Quantum
Software vendor:
Schneider Electric
Schneider Electric
Description
The vulnerability allows a remote attacker to cause the firmware modification.
The vulnerability exists due to improper input validation. A remote attacker can cause an unauthorized firmware modification with possible denial of service (DoS) condition when using Modbus protocol.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.