{"api_version":"1","generated_at":"2026-07-23T22:22:03+00:00","cve":"CVE-2019-6533","urls":{"html":"https://cve.report/CVE-2019-6533","api":"https://cve.report/api/cve/CVE-2019-6533.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-6533","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-6533"},"summary":{"title":"CVE-2019-6533","description":"Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166).","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2019-02-12 17:29:00","updated_at":"2023-01-31 21:03:00"},"problem_types":["CWE-306"],"metrics":[],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-19-036-05","name":"https://ics-cert.us-cert.gov/advisories/ICSA-19-036-05","refsource":"MISC","tags":["Mitigation","Third Party Advisory","US Government Resource"],"title":"Kunbus PR100088 Modbus Gateway (Update B) | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-6533","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6533","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"6533","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"kunbus","cpe5":"pr100088_modbus_gateway","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6533","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"kunbus","cpe5":"pr100088_modbus_gateway","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6533","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"kunbus","cpe5":"pr100088_modbus_gateway_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6533","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"kunbus","cpe5":"pr100088_modbus_gateway_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","DATE_PUBLIC":"2019-02-05T00:00:00","ID":"CVE-2019-6533","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"PR100088 Modbus gateway","version":{"version_data":[{"version_value":"All versions prior to Release R02 (or Software Version 1.1.13166)"}]}}]},"vendor_name":"ICS-CERT"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"MISSING AUTHENTICATION FOR CRITICAL FUNCTION CWE-306"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-19-036-05","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-19-036-05"}]}},"nvd":{"publishedDate":"2019-02-12 17:29:00","lastModifiedDate":"2023-01-31 21:03:00","problem_types":["CWE-306"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:kunbus:pr100088_modbus_gateway_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"r02","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:kunbus:pr100088_modbus_gateway:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"6533","Ordinal":"144264","Title":"CVE-2019-6533","CVE":"CVE-2019-6533","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"6533","Ordinal":"1","NoteData":"Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166).","Type":"Description","Title":null},{"CveYear":"2019","CveId":"6533","Ordinal":"2","NoteData":"2019-02-12","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"6533","Ordinal":"3","NoteData":"2019-02-12","Type":"Other","Title":"Modified"}]}}}