PT-2019-2282 · Schneider Electric · Modicon M241+11

CVE-2019-6820

·

Publicado

2019-05-14

·

Atualizado

2026-05-28

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Modicon M100 versions all Modicon M200 versions all Modicon M221 versions all ATV IMC drive controller versions all Modicon M241 versions all Modicon M251 versions all Modicon M258 versions all Modicon LMC058 versions all Modicon LMC078 versions all PacDrive Eco versions all PacDrive Pro versions all PacDrive Pro2 versions all
Description The issue is related to the absence of authentication for a critical function in the programmable logic controllers Modicon, PacDrive, and ATV IMC. This could allow a remote attacker to modify the device's IP configuration, including the IP address, network mask, and gateway IP address, by sending a specific Ethernet frame.
Recommendations For Modicon M100, update to a version that includes authentication for critical functions. For Modicon M200, update to a version that includes authentication for critical functions. For Modicon M221, update to a version that includes authentication for critical functions. For ATV IMC drive controller, update to a version that includes authentication for critical functions. For Modicon M241, update to a version that includes authentication for critical functions. For Modicon M251, update to a version that includes authentication for critical functions. For Modicon M258, update to a version that includes authentication for critical functions. For Modicon LMC058, update to a version that includes authentication for critical functions. For Modicon LMC078, update to a version that includes authentication for critical functions. For PacDrive Eco, update to a version that includes authentication for critical functions. For PacDrive Pro, update to a version that includes authentication for critical functions. For PacDrive Pro2, update to a version that includes authentication for critical functions. As a temporary workaround, consider restricting access to the Ethernet interface until a patch is available.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02053
BDU:2021-04276
CVE-2019-6820

Produtos afetados

Atv Imc Drive Controller
Modicon Lmc058
Modicon Lmc078
Modicon M100
Modicon M200
Modicon M221
Modicon M241
Modicon M251
Modicon M258
Pacdrive Eco
Pacdrive Pro
Pacdrive Pro2