PT-2019-18365 · Schneider Electric · Modicon M340+1
Published
2019-09-17
·
Updated
2022-02-03
·
CVE-2019-6813
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
BMXNOR0200H Ethernet / Serial RTU module (all firmware versions)
Modicon M340 controller (all firmware versions)
Description
A vulnerability exists that could cause denial of service when truncated SNMP packets on port 161/UDP are received by the device. This issue is related to improper check for unusual or exceptional conditions.
Recommendations
For BMXNOR0200H Ethernet / Serial RTU module, restrict access to port 161/UDP to minimize the risk of exploitation.
For Modicon M340 controller, avoid using the SNMP protocol until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmxnor0200H
Modicon M340