A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Atv Imc Drive Controller
Subscribe
Atv Imc Drive Controller Firmware
Subscribe
Modicon Lmc058
Subscribe
Modicon Lmc058 Firmware
Subscribe
Modicon Lmc078
Subscribe
Modicon Lmc078 Firmware
Subscribe
Modicon M100
Subscribe
Modicon M100 Firmware
Subscribe
Modicon M200
Subscribe
Modicon M200 Firmware
Subscribe
Modicon M221
Subscribe
Modicon M221 Firmware
Subscribe
Modicon M241
Subscribe
Modicon M241 Firmware
Subscribe
Modicon M251
Subscribe
Modicon M251 Firmware
Subscribe
Modicon M258
Subscribe
Modicon M258 Firmware
Subscribe
Pacdrive Eco
Subscribe
Pacdrive Eco Firmware
Subscribe
Pacdrive Pro
Subscribe
Pacdrive Pro2
Subscribe
Pacdrive Pro2 Firmware
Subscribe
Pacdrive Pro Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-16374 | A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T20:31:04.357Z
Reserved: 2019-01-25T00:00:00
Link: CVE-2019-6820
No data.
Status : Modified
Published: 2019-05-22T20:29:02.137
Modified: 2024-11-21T04:47:13.107
Link: CVE-2019-6820
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD