VDB
CVE-2019-6814
CVE-2019-6814
PUBLISHED
CVSS 7.5 HIGH
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.
EPSS 66.93% · 98.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
66.93%
98.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| schneider-electric | net5501-xt_firmware | 0 |
| schneider-electric | net5504_firmware | 0 |
| schneider-electric | net5501-i_firmware | 0 |
| n/a | ÊNET55XX Encoder with firmware prior to version 2.1.9.Ê | ÊNET55XX Encoder with firmware prior to version 2.1.9.Ê |
| Schneider Electric | Modicon M340 | |
| schneider-electric | net5508_firmware | 0 |
| schneider-electric | net5500_firmware | 0 |
| Schneider Electric | N/A | |
| schneider-electric | net5516_firmware | 0 |
| schneider-electric | net5501_firmware | 0 |
Exploit Intelligence
- CIRCL exploited: CVE-2019-6814 (circl-sighting)
- CIRCL seen: CVE-2019-6814 (circl-sighting)
- CIRCL seen: CVE-2019-6814 (circl-sighting)
- CIRCL seen: CVE-2019-6814 (circl-sighting)
- https://www.se.com/ww/en/download/document/SEVD-2019-134-01/ (circl)
- Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass Exploit (0day-today)
- Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass Exploit (0day-today)
Timeline
- May 22, 2019 CVE Published
- Jul 22, 2019 PoC Published
- Jul 29, 2019 PoC Published
- Jul 29, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Apr 20, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
References
- https://www.se.com/ww/en/download/document/SEVD-2019-134-01/ url
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-06+-+Modicon+RTU+Module.pdf&p_Doc_Ref=SEVD-2019-134-06 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-10+-+Modicon+Controller.pdf&p_Doc_Ref=SEVD-2019-134-10 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-05+-+Modicon+Controller.pdf&p_Doc_Ref=SEVD-2019-134-05 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-09+-+Modicon+Quantum.pdf&p_Doc_Ref=SEVD-2019-134-09 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-01+-+Pelco+Endura+NET55XX+Encoder.pdf&p_Doc_Ref=SEVD-2019-134-01 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-04+-Schneider+Electric+Floating+License+Manager.pdf&p_Doc_Ref=SEVD-2019-134-04 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-08+-+Modicon+Quantum.pdf&p_Doc_Ref=SEVD-2019-134-08 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-03+-+Modicon+Controller.pdf&p_Doc_Ref=SEVD-2019-134-03 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-02+-+Modicon+and+PacDrive+controllers.pdf&p_Doc_Ref=SEVD-2019-134-02 advisory
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2019-134-07+-+ConneXium+Gateway.pdf&p_Doc_Ref=SEVD-2019-134-07 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-6814 advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-01 url
- https://www.se.com/ww/en/download/document/SEVD-2019-134-01 url