SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6849

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the…

HIGH 7.5EPSS 1.71%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.71% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
schneider-electric/modicon m580 firmware · schneider-electric/modicon bmenoc 0311 firmware · schneider-electric/modicon bmenoc 0321 firmware
Source
cybersecurity@se.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.