A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2
References
Link | Resource |
---|---|
https://www.schneider-electric.com/en/download/document/SEVD-2019-134-02/ | Vendor Advisory |
https://www.schneider-electric.com/en/download/document/SEVD-2019-134-02/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
History
21 Nov 2024, 04:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.schneider-electric.com/en/download/document/SEVD-2019-134-02/ - Vendor Advisory |
03 Feb 2022, 14:29
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:se:modicon_m241_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m251_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m221:-:*:*:*:*:*:*:* |
cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m251_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m221:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m258_firmware:*:*:*:*:*:*:*:* |
31 Jan 2022, 19:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:se:modicon_m258:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m251:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m100:-:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m241:-:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m221_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m100_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:o:schneider-electric:modicon_m100_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m251:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m241:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m258:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m100:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m200:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m221_firmware:*:*:*:*:*:*:*:* |
26 Aug 2021, 14:43
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:schneider-electric:modicon_m251:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m200:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m258:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m241:-:*:*:*:*:*:*:* |
cpe:2.3:h:se:modicon_m100:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m200:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m251:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m241:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m258:-:*:*:*:*:*:*:* |
19 Aug 2021, 18:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:schneider-electric:modicon_m100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m221_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m258_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m221:-:*:*:*:*:*:*:* |
cpe:2.3:o:se:modicon_m258_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m251_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m241_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m221_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m221:-:*:*:*:*:*:*:* |
Information
Published : 2019-05-22 20:29
Updated : 2024-11-21 04:47
NVD link : CVE-2019-6820
Mitre link : CVE-2019-6820
CVE.ORG link : CVE-2019-6820
JSON object : View
Products Affected
schneider-electric
- pacdrive_pro
- modicon_lmc078
- modicon_m221
- pacdrive_pro_firmware
- pacdrive_pro2_firmware
- modicon_m221_firmware
- modicon_lmc058_firmware
- modicon_m100_firmware
- modicon_lmc058
- atv_imc_drive_controller_firmware
- modicon_m200_firmware
- modicon_m258_firmware
- modicon_m258
- modicon_m251
- modicon_lmc078_firmware
- pacdrive_eco_firmware
- atv_imc_drive_controller
- pacdrive_pro2
- modicon_m200
- modicon_m100
- modicon_m241_firmware
- pacdrive_eco
- modicon_m251_firmware
- modicon_m241
CWE
CWE-306
Missing Authentication for Critical Function