5
CVSSv2

CVE-2019-6848

Published: 29/10/2019 Updated: 19/04/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric modicon_m580_firmware -

schneider-electric modicon_bmenoc_0311_firmware -

schneider-electric modicon_bmenoc_0321_firmware -