CVE-2019-6849
Summary
| CVE | CVE-2019-6849 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-29 19:15:00 UTC |
| Updated | 2019-11-01 13:45:00 UTC |
| Description | A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Notification - Modicon Controllers (V2.0) | Schneider Electric |
CONFIRM |
www.schneider-electric.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591011 Schneider Electric Modicon M580 Controllers and Communication Modules Multiple Vulnerabilities (SEVD-2019-281-04)