CVE-2019-6820 Information

Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100 Modicon M200 Modicon M221 ATV IMC drive controller Modicon M241 Modicon M251 Modicon M258 Modicon LMC058 Modicon LMC078 PacDrive Eco PacDrive Pro PacDrive Pro2

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Reference

https://www.schneider-electric.com/en/download/document/SEVD-2019-134-02/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

HIGH

Base Severity

8.2

Share on: