PT-2019-6003 · Schneider Electric · Magelis Hmi Panels

Published

2019-09-13

·

Updated

2025-09-30

·

CVE-2019-6833

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Magelis HMI Panels versions all
Description A vulnerability exists due to improper check for unusual or exceptional conditions, which could cause a temporary freeze of the HMI when a high rate of frames is received. Once the attack stops, the buffered commands are processed by the HMI panel. The issue is also related to insufficient checking of unusual or exceptional states in the software, allowing a remote attacker to cause a denial of service.
Recommendations For all versions of Magelis HMI Panels, consider implementing measures to limit the rate of frames received to prevent the temporary freeze of the HMI panel. As a temporary workaround, restrict the input of high-rate frames until a more permanent solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04279
CVE-2019-6833

Affected Products

Magelis Hmi Panels