Insufficient Randomness Vulnerability in Modicon Ethernet Communication by Schneider Electric
CVE-2019-6821
6.5MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 22 May 2019
What is CVE-2019-6821?
The vulnerability involves the use of insufficiently random values, making it possible for attackers to hijack TCP connections over Ethernet communication. This flaw affects multiple Schneider Electric Modicon firmware versions, opening avenues for unauthorized access and potential control of network devices.
Affected Version(s)
Modicon Controllers, Modicon M580 firmware prior to V2.30, and all firmware of Modicon M340, Modicon Premium, Modicon Quantum Modicon Controllers, Modicon M580 firmware versions prior to V2.30, and all firmware versions of Modicon M340, Modicon Premium, Modicon Quantum