Cleartext Transmission Vulnerability in Modicon Products by Schneider Electric
CVE-2019-6845
7.5HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 29 October 2019
Summary
A vulnerability exists in the Modicon series of products by Schneider Electric, specifically affecting the Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum across all firmware versions. This vulnerability arises from the cleartext transmission of sensitive information during application transfers via the Modbus TCP protocol. Organizations using these products should assess their configurations and consider implementing measures to secure data in transit to prevent potential information disclosure.
Affected Version(s)
Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware ) Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions)
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved