SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-6859

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded…

HIGH 7.5EPSS 1.18%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.18% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-798
Affected
schneider-electric/bmx p34x firmware · schneider-electric/bmx noe 0100 firmware · schneider-electric/bmx noe 0110 firmware · schneider-electric/bmx noc 0401 firmware · schneider-electric/tsx p57x firmware · schneider-electric/tsx ety x103 firmware · schneider-electric/140 cpu6x firmware · schneider-electric/140 noe 771x1 firmware · schneider-electric/140 noc 78x00 firmware · schneider-electric/140 noc 77101 firmware
Source
cybersecurity@se.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.