CyberSec.Space Logo
Back to CVE Browser

CVE-2019-6852

HIGH
7.5
CVSS Severity Score
EPSS Score0.1020%
EPSS Percentile25.55th
PublishedNov 20, 2019
Last ModifiedMay 28, 2026

Vulnerability Description

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

Affected Platforms (CPE)

πŸ’»
Schneider Electric

Bmx P34x Firmware

All versions
πŸ’»
Schneider Electric

Bmx Noe 0100 Firmware

All versions
πŸ’»
Schneider Electric

Bmx Noe 0110 Firmware

All versions
πŸ’»
Schneider Electric

Bmx Noc 0401 Firmware

All versions
πŸ’»
Schneider Electric

Tsx P57x Firmware

All versions
πŸ’»
Schneider Electric

Tsx Ety X103 Firmware

All versions
πŸ’»
Schneider Electric

140 Cpu6x Firmware

All versions
πŸ’»
Schneider Electric

140 Noe 771x1 Firmware

All versions
πŸ’»
Schneider Electric

140 Noc 78x00 Firmware

All versions
πŸ’»
Schneider Electric

140 Noc 77101 Firmware

All versions

References & Advisories

Related Vulnerabilities