PT-2019-2340 · Schneider Electric · Modicon Quantum

Vyacheslav Moskvin And Ivan Kurnakov

·

Published

2019-05-14

·

Updated

2020-08-24

·

CVE-2019-6815

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Modicon Quantum all firmware versions
Description The issue is related to errors in access control mechanisms, which could allow a remote attacker to cause a denial of service or make unauthorized modifications to the PLC configuration when using the Ethernet/IP protocol. The vulnerability is associated with permissions, privileges, and access control flaws.
Recommendations For all firmware versions, consider restricting access to the Ethernet/IP protocol until a patch is available. As a temporary workaround, limit the privileges of users who can modify the PLC configuration to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02115
BDU:2021-04193
CVE-2019-6815

Affected Products

Modicon Quantum