CVE-2019-6852

HIGHCVSS 7.5/10EPSS 1.37%

Last modified

CVE-2019-6852 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.

Description

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.37%

68.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Schneider-ElectricBmx P34x FirmwareAll versions
Schneider-ElectricBmx Noe 0100 FirmwareAll versions
Schneider-ElectricBmx Noe 0110 FirmwareAll versions
Schneider-ElectricBmx Noc 0401 FirmwareAll versions
Schneider-ElectricTsx P57x FirmwareAll versions
Schneider-ElectricTsx Ety X103 FirmwareAll versions
Schneider-Electric140 Cpu6x FirmwareAll versions
Schneider-Electric140 Noe 771x1 FirmwareAll versions
Schneider-Electric140 Noc 78x00 FirmwareAll versions
Schneider-Electric140 Noc 77101 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-6852?
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
How severe is CVE-2019-6852?
CVE-2019-6852 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.37% probability of exploitation in the next 30 days.
How do I fix CVE-2019-6852?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-6852?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST