SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6852

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific…

HIGH 7.5EPSS 1.38%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.38% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
schneider-electric/bmx p34x firmware · schneider-electric/bmx noe 0100 firmware · schneider-electric/bmx noe 0110 firmware · schneider-electric/bmx noc 0401 firmware · schneider-electric/tsx p57x firmware · schneider-electric/tsx ety x103 firmware · schneider-electric/140 cpu6x firmware · schneider-electric/140 noe 771x1 firmware · schneider-electric/140 noc 78x00 firmware · schneider-electric/140 noc 77101 firmware
Source
cybersecurity@se.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.