Vulnerabilities > CVE-2019-6855 - Incorrect Authorization vulnerability in Schneider-Electric products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
schneider-electric
CWE-863

Summary

Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.

Vulnerable Configurations

Part Description Count
Application
Schneider-Electric
4
OS
Schneider-Electric
106
Hardware
Schneider-Electric
21

Common Weakness Enumeration (CWE)