CVE-2019-6810 PUBLISHED CVSS 8.800000190734863 HIGH

CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the execution of commands by unauthorized users when using IEC 60870-5-104 protocol.

EPSS 0.50% · 65.6th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.50%
65.6th percentile

Affected Products

VendorProductVersions
schneider-electricbmxnor0200h_firmware
Schneider Electric SEBMXNOR0200H Ethernet / Serial RTU moduleall firmware versions

Timeline

References

Open in Interactive Console →