ID

VAR-201910-0584


CVE

CVE-2019-6851


TITLE

plural Modicon Information disclosure vulnerability in products

Trust: 0.8

sources: JVNDB: JVNDB-2019-011632

DESCRIPTION

A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol

Trust: 1.62

sources: NVD: CVE-2019-6851 // JVNDB: JVNDB-2019-011632

AFFECTED PRODUCTS

vendor:schneider electricmodel:tsxmcpc512kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpc768kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:modicon m340scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpc003mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpf008mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfpp384kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmcpc002mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpc01m7scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfp0128p2scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpp384kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpc002mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfp064p2scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfpp512kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfpp004mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:modicon m580scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpc448kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfpp224kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfpp001mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpc007mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpf004mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmfpp002mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpc001mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxmrpp224kscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:modicon m340scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:modicon m580scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmcpc002mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmcpc512kscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmfpp001mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmfpp002mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmfpp004mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmfpp512kscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmrpc001mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxmrpc002mscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2019-011632 // NVD: CVE-2019-6851

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2019-6851
value: HIGH

Trust: 1.8

CNNVD: CNNVD-201910-400
value: HIGH

Trust: 0.6

NVD: CVE-2019-6851
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2019-6851
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2019-6851
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2019-011632 // CNNVD: CNNVD-201910-400 // NVD: CVE-2019-6851

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

problemtype:CWE-538

Trust: 0.8

sources: JVNDB: JVNDB-2019-011632 // NVD: CVE-2019-6851

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201910-400

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201910-400

CONFIGURATIONS

sources: NVD: CVE-2019-6851

PATCH

title:SEVD-2019-281-01url:https://www.se.com/ww/en/download/document/sevd-2019-281-01/

Trust: 0.8

sources: JVNDB: JVNDB-2019-011632

EXTERNAL IDS

db:NVDid:CVE-2019-6851

Trust: 2.4

db:SCHNEIDERid:SEVD-2019-281-01

Trust: 1.6

db:JVNDBid:JVNDB-2019-011632

Trust: 0.8

db:TALOSid:TALOS-2019-0851

Trust: 0.6

db:CNNVDid:CNNVD-201910-400

Trust: 0.6

sources: JVNDB: JVNDB-2019-011632 // CNNVD: CNNVD-201910-400 // NVD: CVE-2019-6851

REFERENCES

url:https://www.schneider-electric.com/ww/en/download/document/sevd-2019-281-01

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-6851

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-6851

Trust: 0.8

url:https://www.talosintelligence.com/vulnerability_reports/talos-2019-0851

Trust: 0.6

sources: JVNDB: JVNDB-2019-011632 // CNNVD: CNNVD-201910-400 // NVD: CVE-2019-6851

SOURCES

db:JVNDBid:JVNDB-2019-011632
db:CNNVDid:CNNVD-201910-400
db:NVDid:CVE-2019-6851

LAST UPDATE DATE

2022-05-04T09:55:56.268000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2019-011632date:2019-11-14T00:00:00
db:CNNVDid:CNNVD-201910-400date:2022-03-10T00:00:00
db:NVDid:CVE-2019-6851date:2022-02-03T16:10:00

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2019-011632date:2019-11-14T00:00:00
db:CNNVDid:CNNVD-201910-400date:2019-10-08T00:00:00
db:NVDid:CVE-2019-6851date:2019-10-29T19:15:00