Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-6820


A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2


Published

2019-05-22T20:29:02.137

Last Modified

2024-11-21T04:47:13.107

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-306
  • Type: Primary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric modicon_m100_firmware * Yes
Hardware schneider-electric modicon_m100 - No
Operating System schneider-electric modicon_m200_firmware * Yes
Hardware schneider-electric modicon_m200 - No
Operating System schneider-electric modicon_m221_firmware * Yes
Hardware schneider-electric modicon_m221 - No
Operating System schneider-electric atv_imc_drive_controller_firmware * Yes
Hardware schneider-electric atv_imc_drive_controller - No
Operating System schneider-electric modicon_m241_firmware * Yes
Hardware schneider-electric modicon_m241 - No
Operating System schneider-electric modicon_m251_firmware * Yes
Hardware schneider-electric modicon_m251 - No
Operating System schneider-electric modicon_m258_firmware * Yes
Hardware schneider-electric modicon_m258 - No
Operating System schneider-electric modicon_lmc058_firmware * Yes
Hardware schneider-electric modicon_lmc058 - No
Operating System schneider-electric modicon_lmc078_firmware * Yes
Hardware schneider-electric modicon_lmc078 - No
Operating System schneider-electric pacdrive_eco_firmware * Yes
Hardware schneider-electric pacdrive_eco - No
Operating System schneider-electric pacdrive_pro_firmware * Yes
Hardware schneider-electric pacdrive_pro - No
Operating System schneider-electric pacdrive_pro2_firmware * Yes
Hardware schneider-electric pacdrive_pro2 - No

References