Description
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
Published: 2019-11-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-16406 A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
History

No history.

Subscriptions

Schneider-electric 140 Cpu6x 140 Cpu6x Firmware 140 Noc 77101 140 Noc 77101 Firmware 140 Noc 78x00 140 Noc 78x00 Firmware 140 Noe 771x1 140 Noe 771x1 Firmware Bmx Noc 0401 Bmx Noc 0401 Firmware Bmx Noe 0100 Bmx Noe 0100 Firmware Bmx Noe 0110 Bmx Noe 0110 Firmware Bmx P34x Bmx P34x Firmware Tsx Ety X103 Tsx Ety X103 Firmware Tsx P57x Tsx P57x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T20:31:04.426Z

Reserved: 2019-01-25T00:00:00.000Z

Link: CVE-2019-6852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-20T22:15:12.030

Modified: 2024-11-21T04:47:16.920

Link: CVE-2019-6852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses