7.5
CVE-2019-6850
- EPSS 0.32%
- Published 29.10.2019 19:15:22
- Last modified 21.11.2024 04:47:16
- Source cybersecurity@se.com
- Teams watchlist Login
- Open Login
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.
Data is provided by the National Vulnerability Database (NVD)
Schneider-electric ≫ Modicon M580 Firmware Version-
Schneider-electric ≫ Modicon Bmenoc 0311 Firmware Version-
Schneider-electric ≫ Modicon Bmenoc 0321 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.32% | 0.545 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.