CVE-2019-6859

moderate-risk
Published 2020-04-22

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

Do I need to act?

-
0.34% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (10)

Bmx P34X Firmware
Bmx Noe 0100 Firmware
Bmx Noe 0110 Firmware
Bmx Noc 0401 Firmware
Tsx P57X Firmware
Tsx Ety X103 Firmware
140 Cpu6X Firmware
140 Noe 771X1 Firmware
140 Noc 78X00 Firmware
140 Noc 77101 Firmware

Affected Vendors

43
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 1/34 · Minimal
Exposure 16/34 · Moderate