CVE-2019-6821
CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when using Ethernet communication in Modicon M580 firmware versions prior to V2.30, and all firmware versions of Modicon M340, Modicon…
Does this matter?
Lower severity and a low EPSS score (1.93%). Track it; it rarely justifies an emergency change on its own.
Description
CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when using Ethernet communication in Modicon M580 firmware versions prior to V2.30, and all firmware versions of Modicon M340, Modicon Premium, Modicon Quantum.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-330
- Affected
- schneider-electric/modicon m580 firmware · schneider-electric/modicon m340 firmware · schneider-electric/modicon quantum firmware · schneider-electric/modicon premium firmware
- Source
- cybersecurity@se.com
References
- http://www.securityfocus.com/bid/108366Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-136-01Third Party Advisory, US Government Resource
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-03/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/108366Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-136-01Third Party Advisory, US Government Resource
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-03/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.