Cleartext Transmission Vulnerability in Schneider Electric Modicon Devices
CVE-2019-6846
6.5MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 29 October 2019
Summary
A vulnerability exists in various Schneider Electric Modicon devices, including the M580, M340, BMxCRA, and 140CRA modules, due to the unencrypted transmission of sensitive data over the FTP protocol. This flaw could allow unauthorized parties to capture sensitive information during transmission, potentially compromising the security of the system. Users are advised to ensure secure data transfer methods are employed and to monitor for any unauthorized access.
Affected Version(s)
Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware ) Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions)
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved