6.5

CVE-2019-6833

A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.

Data is provided by the National Vulnerability Database (NVD)
Schneider-electricHmigto Firmware Version-
   Schneider-electricHmigto1300 Version-
   Schneider-electricHmigto1310 Version-
   Schneider-electricHmigto2300 Version-
   Schneider-electricHmigto2310 Version-
   Schneider-electricHmigto2315 Version-
   Schneider-electricHmigto3510 Version-
   Schneider-electricHmigto4310 Version-
   Schneider-electricHmigto5310 Version-
   Schneider-electricHmigto5315 Version-
   Schneider-electricHmigto6310 Version-
   Schneider-electricHmigto6315 Version-
Schneider-electricHmisto Firmware Version-
   Schneider-electricHmisto501 Version-
   Schneider-electricHmisto511 Version-
   Schneider-electricHmisto512 Version-
   Schneider-electricHmisto531 Version-
   Schneider-electricHmisto532 Version-
   Schneider-electricHmisto705 Version-
   Schneider-electricHmisto715 Version-
   Schneider-electricHmisto735 Version-
Schneider-electricHmigtu Firmware Version-
   Schneider-electricHmig2u Version-
   Schneider-electricHmig3u Version-
   Schneider-electricHmig3ufc Version-
   Schneider-electricHmig5u Version-
   Schneider-electricHmig5u2 Version-
   Schneider-electricHmig5ufc Version-
   Schneider-electricHmig5ul8a Version-
Schneider-electricHmiscu Firmware Version-
   Schneider-electricHmiscu6a5 Version-
   Schneider-electricHmiscu6b5 Version-
   Schneider-electricHmiscu8a5 Version-
   Schneider-electricHmiscu8b5 Version-
Schneider-electricHmistu Firmware Version-
   Schneider-electricHmistu655 Version-
   Schneider-electricHmistu655w Version-
   Schneider-electricHmistu855 Version-
   Schneider-electricHmistu855w Version-
Schneider-electricXbtgt Firmware Version-
   Schneider-electricXbtgt2430 Version-
   Schneider-electricXbtgt2930 Version-
Schneider-electricHmigxu Firmware Version-
   Schneider-electricHmigxu35 Version-
   Schneider-electricHmigxu55 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.539
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.