Improper Check for Unusual or Exceptional Conditions in Schneider Electric Ethernet / Serial RTU Module
CVE-2019-6831
8.6HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 17 September 2019
Summary
A vulnerability in the BMXNOR0200H Ethernet / Serial RTU module, present across all firmware versions, allows for unintended disconnection of active connections. This occurs when the module receives an excessive amount of IEC 60870-5-104 packets on TCP port 2404, highlighting the need for robust network management and security measures. Mitigating this vulnerability is crucial for maintaining reliable communication in industrial applications.
Affected Version(s)
BMXNOR0200H Ethernet / Serial RTU module all firmware versions
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved