PT-2019-3857 · Schneider Electric · Modicon M340+3
Publicado
2019-10-08
·
Atualizado
2022-02-03
·
CVE-2019-6845
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Modicon M580 (all firmware versions)
Modicon M340 (all firmware versions)
Modicon Premium (all firmware versions)
Modicon Quantum (all firmware versions)
Description
A Cleartext Transmission of Sensitive Information issue exists, which could cause the disclosure of information when transferring applications to the controller using the Modbus TCP protocol. This could allow a remote attacker to reveal protected information.
Recommendations
For Modicon M580, consider disabling the use of Modbus TCP protocol until a fix is available.
For Modicon M340, restrict access to the controller when transferring applications to minimize the risk of exploitation.
For Modicon Premium, avoid using the Modbus TCP protocol for sensitive information transfer until the issue is resolved.
For Modicon Quantum, as a temporary workaround, consider using alternative protocols for transferring applications to the controller until a patch is available.
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Modicon M340
Modicon M580
Modicon Premium
Modicon Quantum