Cleartext Transmission Vulnerability in Modicon Products by Schneider Electric
CVE-2019-6845

7.5HIGH

Summary

A vulnerability exists in the Modicon series of products by Schneider Electric, specifically affecting the Modicon M580, Modicon M340, Modicon Premium, and Modicon Quantum across all firmware versions. This vulnerability arises from the cleartext transmission of sensitive information during application transfers via the Modbus TCP protocol. Organizations using these products should assess their configurations and consider implementing measures to secure data in transit to prevent potential information disclosure.

Affected Version(s)

Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware ) Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions)

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.