CVE-2019-6846 Information
Feb 14, 2021
cve
Description
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580 Modicon M340 Modicon BMxCRA and 140CRA modules (all firmware versions) which could cause information disclosure when using the FTP protocol.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Reference
https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-281-02
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: