CVE-2019-6859

HIGHCVSS 7.5/10EPSS 1.32%

Last modified

CVE-2019-6859 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.. EPSS estimates a 1.32% chance of exploitation in the next 30 days.

Description

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.32%

67.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Schneider-ElectricBmx P34x FirmwareAll versions
Schneider-ElectricBmx Noe 0100 FirmwareAll versions
Schneider-ElectricBmx Noe 0110 FirmwareAll versions
Schneider-ElectricBmx Noc 0401 FirmwareAll versions
Schneider-ElectricTsx P57x FirmwareAll versions
Schneider-ElectricTsx Ety X103 FirmwareAll versions
Schneider-Electric140 Cpu6x FirmwareAll versions
Schneider-Electric140 Noe 771x1 FirmwareAll versions
Schneider-Electric140 Noc 78x00 FirmwareAll versions
Schneider-Electric140 Noc 77101 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-6859?
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
How severe is CVE-2019-6859?
CVE-2019-6859 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.32% probability of exploitation in the next 30 days.
How do I fix CVE-2019-6859?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-6859?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST