CVE-2019-6813
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/09/2019
Last modified:
17/06/2026
Description
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions) and Modicon M340 controller (all firmware versions), which could cause denial of service when truncated SNMP packets on port 161/UDP are received by the device.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:schneider-electric:modicon_m340_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:modicon_m340:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:bmxnor0200h_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:bmxnor0200h:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://security.cse.iitk.ac.in/responsible-disclosure
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-02/
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/
- https://security.cse.iitk.ac.in/responsible-disclosure
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-02/
- https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/



