CVE-2019-6813
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions) and Modicon M340 controller (all firmware versions), which could cause denial of service when…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions) and Modicon M340 controller (all firmware versions), which could cause denial of service when truncated SNMP packets on port 161/UDP are received by the device.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-754
- Affected
- schneider-electric/modicon m340 firmware · schneider-electric/bmxnor0200h firmware
- Source
- cybersecurity@se.com
References
- https://security.cse.iitk.ac.in/responsible-disclosureThird Party Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-02/Vendor Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/Vendor Advisory
- https://security.cse.iitk.ac.in/responsible-disclosureThird Party Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-02/Vendor Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.