Learn about CVE-2019-6847 affecting Modicon M580, M340, and BMxCRA/140CRA modules. Discover the impact, affected systems, exploitation, and mitigation steps.
A vulnerability known as CWE-755 affects Modicon M580, Modicon M340, and Modicon BMxCRA / 140CRA modules, potentially leading to a Denial of Service attack on the FTP service.
Understanding CVE-2019-6847
This CVE involves an improper handling of exceptional conditions in Schneider Electric's Modicon devices.
What is CVE-2019-6847?
The vulnerability in Modicon M580, Modicon M340, and Modicon BMxCRA / 140CRA modules could result in a Denial of Service attack on the FTP service during firmware upgrades.
The Impact of CVE-2019-6847
The vulnerability affects all firmware versions of the mentioned Modicon devices, posing a risk of service disruption through a Denial of Service attack.
Technical Details of CVE-2019-6847
This section provides detailed technical insights into the CVE.
Vulnerability Description
The vulnerability, categorized as CWE-755, arises from improper handling of exceptional conditions in the Modicon devices, potentially leading to a Denial of Service attack on the FTP service.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited when attempting to upgrade the firmware using an incompatible version with the application in the controller via FTP protocol.
Mitigation and Prevention
Protecting systems from CVE-2019-6847 is crucial to ensure security.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates