PT-2019-2335 · Schneider Electric · Modicon M580+3

Jared Rittle

·

Published

2019-05-14

·

Updated

2022-02-03

·

CVE-2019-6808

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Modicon M580 (affected versions not specified) Modicon M340 (affected versions not specified) Modicon Quantum (affected versions not specified) Modicon Premium (affected versions not specified)
Description A remote code execution issue exists due to improper access control, which could allow an attacker to overwrite configuration settings of the controller using the Modbus protocol. This could potentially lead to arbitrary code execution.
Recommendations For Modicon M580, update the firmware to a version that addresses the improper access control issue. For Modicon M340, restrict access to the Modbus protocol until a patch is available. For Modicon Quantum, consider disabling remote configuration capabilities via Modbus as a temporary workaround. For Modicon Premium, avoid using the Modbus protocol for configuration changes until the issue is resolved. As a general mitigation measure, restrict access to the Modbus protocol to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02110
CVE-2019-6808

Affected Products

Modicon M340
Modicon M580
Modicon Premium
Modicon Quantum