PT-2019-2340 · Schneider Electric · Modicon Quantum
Vyacheslav Moskvin And Ivan Kurnakov
·
Published
2019-05-14
·
Updated
2020-08-24
·
CVE-2019-6815
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Modicon Quantum all firmware versions
Description
The issue is related to errors in access control mechanisms, which could allow a remote attacker to cause a denial of service or make unauthorized modifications to the PLC configuration when using the Ethernet/IP protocol. The vulnerability is associated with permissions, privileges, and access control flaws.
Recommendations
For all firmware versions, consider restricting access to the Ethernet/IP protocol until a patch is available. As a temporary workaround, limit the privileges of users who can modify the PLC configuration to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modicon Quantum