6.4
CVSSv2

CVE-2019-6820

Published: 22/05/2019 Updated: 03/02/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric modicon_m100_firmware

schneider-electric modicon_m200_firmware

schneider-electric modicon_m221_firmware

schneider-electric atv_imc_drive_controller_firmware

schneider-electric modicon_m241_firmware

schneider-electric modicon_m251_firmware

schneider-electric modicon_m258_firmware

schneider-electric modicon_lmc058_firmware

schneider-electric modicon_lmc078_firmware

schneider-electric pacdrive_eco_firmware

schneider-electric pacdrive_pro_firmware

schneider-electric pacdrive_pro2_firmware