Vulnerabilities > CVE-2019-6828 - Improper Handling of Exceptional Conditions vulnerability in Schneider-Electric products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Talos
id | TALOS-2019-0806 |
last seen | 2019-09-19 |
published | 2019-08-13 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0806 |
title | Schneider Electric Modicon M580 UMAS Read System Coils and Registers Denial of Service Vulnerability |