Denial of Service Vulnerability in Modicon M580 and Communication Module by Schneider Electric
CVE-2019-6848
8.6HIGH
Summary
An improper handling of exceptional conditions vulnerability has been identified in the Modicon M580 CPU and its associated communication modules. This flaw can be exploited by sending specifically crafted data through the REST API, which may result in a Denial of Service (DoS) condition on the affected PLCs. Organizations using these devices should implement necessary security measures to mitigate potential attacks and safeguard their operations.
Affected Version(s)
Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info) Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info)
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved