Improper Check for Unusual or Exceptional Conditions in Schneider Electric Ethernet / Serial RTU Module
CVE-2019-6831

8.6HIGH

Key Information:

Vendor
CVE Published:
17 September 2019

Summary

A vulnerability in the BMXNOR0200H Ethernet / Serial RTU module, present across all firmware versions, allows for unintended disconnection of active connections. This occurs when the module receives an excessive amount of IEC 60870-5-104 packets on TCP port 2404, highlighting the need for robust network management and security measures. Mitigating this vulnerability is crucial for maintaining reliable communication in industrial applications.

Affected Version(s)

BMXNOR0200H Ethernet / Serial RTU module all firmware versions

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.