7.5

CVE-2019-6819

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the products: Modicon M340 - firmware versions prior to V3.01, Modicon M580 - firmware versions prior to V2.80, All firmware versions of Modicon Quantum and Modicon Premium.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electricModicon M580 Firmware Version < 2.80
   Schneider-electricBmeh582040 Version-
   Schneider-electricBmeh582040c Version-
   Schneider-electricBmeh584040 Version-
   Schneider-electricBmeh584040c Version-
   Schneider-electricBmeh586040 Version-
   Schneider-electricBmeh586040c Version-
   Schneider-electricModicon M580 Bmep581020 Version-
   Schneider-electricModicon M580 Bmep581020h Version-
   Schneider-electricModicon M580 Bmep582020 Version-
   Schneider-electricModicon M580 Bmep582020h Version-
   Schneider-electricModicon M580 Bmep582040 Version-
   Schneider-electricModicon M580 Bmep582040h Version-
   Schneider-electricModicon M580 Bmep582040s Version-
   Schneider-electricModicon M580 Bmep583020 Version-
   Schneider-electricModicon M580 Bmep583040 Version-
   Schneider-electricModicon M580 Bmep584020 Version-
   Schneider-electricModicon M580 Bmep584040 Version-
   Schneider-electricModicon M580 Bmep584040s Version-
   Schneider-electricModicon M580 Bmep585040 Version-
   Schneider-electricModicon M580 Bmep585040c Version-
   Schneider-electricModicon M580 Bmep586040 Version-
   Schneider-electricModicon M580 Bmep586040c Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.632
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.