Vulnerabilities > Schneider Electric > Modicon Bmenoc 0321 Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-10-29 CVE-2019-6850 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.
network
low complexity
schneider-electric CWE-200
5.0
2019-10-29 CVE-2019-6849 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.
network
low complexity
schneider-electric CWE-200
5.0
2019-10-29 CVE-2019-6848 Improper Handling of Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.
network
low complexity
schneider-electric CWE-755
5.0