CVE-2019-6852
—CVSS 3.1
7.5 high
EPSS
1%p70
Published
()
Modified
Description
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
- Vendors
- schneider-electric
- Products
- bmx p34x firmware, bmx noe 0100 firmware, bmx noe 0110 firmware, bmx noc 0401 firmware, tsx p57x firmware, tsx ety x103 firmware, 140 cpu6x firmware, 140 noe 771x1 firmware, 140 noc 78x00 firmware, 140 noc 77101 firmware
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.