CVE-2019-6859
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- schneider-electric/bmx p34x firmware · schneider-electric/bmx noe 0100 firmware · schneider-electric/bmx noe 0110 firmware · schneider-electric/bmx noc 0401 firmware · schneider-electric/tsx p57x firmware · schneider-electric/tsx ety x103 firmware · schneider-electric/140 cpu6x firmware · schneider-electric/140 noe 771x1 firmware · schneider-electric/140 noc 78x00 firmware · schneider-electric/140 noc 77101 firmware
- Source
- cybersecurity@se.com
References
- https://www.se.com/ww/en/download/document/SEVD-2019-316-02Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2019-316-02Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.