7.5
CVSSv2

CVE-2019-6855

Published: 06/01/2020 Updated: 31/01/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions before 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric unity pro

schneider-electric ecostruxure control expert

schneider-electric ecostruxure control expert 14.1

schneider-electric modicon_m580_bmep584040_firmware

schneider-electric modicon_m580_bmeh584040_firmware

schneider-electric modicon_m580_bmep586040_firmware

schneider-electric modicon_m580_bmeh586040_firmware

schneider-electric modicon_m580_bmep581020_firmware

schneider-electric modicon_m580_bmep582020_firmware

schneider-electric modicon_m580_bmep582040_firmware

schneider-electric modicon_m580_bmep583020_firmware

schneider-electric modicon_m580_bmep583040_firmware

schneider-electric modicon_m580_bmep584020_firmware

schneider-electric modicon_m580_bmep585040_firmware

schneider-electric modicon_m580_bmeh582040_firmware

schneider-electric modicon_m580_bmep584040s_firmware

schneider-electric modicon_m580_bmeh584040s_firmware

schneider-electric modicon_m580_bmeh586040s_firmware

schneider-electric modicon_m580_bmep582040s_firmware

schneider-electric modicon_m340_bmxp3420302_firmware

schneider-electric modicon_m340_bmxp342020_firmware

schneider-electric modicon_m340_bmxp342000_firmware

schneider-electric modicon_m340_bmxp341000_firmware

schneider-electric modicon_m340_bmxp3420102_firmware