Description
A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.
Published: 2019-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-16387 A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.
History

Tue, 30 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Schneider-electric Hmig2u Hmig3u Hmig3ufc Hmig5u Hmig5u2 Hmig5ufc Hmig5ul8a Hmigto1300 Hmigto1310 Hmigto2300 Hmigto2310 Hmigto2315 Hmigto3510 Hmigto4310 Hmigto5310 Hmigto5315 Hmigto6310 Hmigto6315 Hmigto Firmware Hmigtu Firmware Hmigxo Hmigxo Firmware Hmigxu35 Hmigxu55 Hmigxu Firmware Hmiscu6a5 Hmiscu6b5 Hmiscu8a5 Hmiscu8b5 Hmiscu Firmware Hmisto501 Hmisto511 Hmisto512 Hmisto531 Hmisto532 Hmisto705 Hmisto715 Hmisto735 Hmisto Firmware Hmistu655 Hmistu655w Hmistu855 Hmistu855w Hmistu Firmware Xbtgh2460 Xbtgh Firmware Xbtgt2430 Xbtgt2930 Xbtgt Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2025-09-30T14:36:19.669Z

Reserved: 2019-01-25T00:00:00.000Z

Link: CVE-2019-6833

cve-icon Vulnrichment

Updated: 2024-08-04T20:31:04.400Z

cve-icon NVD

Status : Modified

Published: 2019-09-17T20:15:12.467

Modified: 2025-09-30T15:15:39.103

Link: CVE-2019-6833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses