« Volver al listado

CVE-2019-6840

Estado: ModificadaCrítica (9.8)—

A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to send a crafted message to the target server, thereby causing arbitrary commands to be executed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-6840",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@se.com",
      "affectedData": [
        {
          "vendor": "Schneider Electric SE",
          "product": "U.motion Server",
          "versions": [
            {
              "status": "affected",
              "version": "MEG6501-0001 - U.motion KNX server"
            },
            {
              "status": "affected",
              "version": "MEG6501-0002 - U.motion KNX Server Plus"
            },
            {
              "status": "affected",
              "version": "MEG6260-0410 - U.motion KNX Server Plus"
            },
            {
              "status": "affected",
              "version": "Touch 10"
            },
            {
              "status": "affected",
              "version": "MEG6260-0415 - U.motion KNX Server Plus"
            },
            {
              "status": "affected",
              "version": "Touch 15"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-09-17T20:15:12.843",
  "references": [
    {
      "url": "https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-253-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cybersecurity@se.com"
    },
    {
      "url": "https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-253-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@se.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-134"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-134"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to send a crafted message to the target server, thereby causing arbitrary commands to be executed."
    },
    {
      "lang": "es",
      "value": "Una Cadena de Formato: Se presenta una vulnerabilidad CWE-134 en U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), lo que podría permitir a un atacante enviar un mensaje diseñado hacia servidor de destino, causando de este modo comandos arbitrarios a ser ejecutados."
    }
  ],
  "lastModified": "2026-06-17T02:39:46.570",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6501-0001_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "716CA99C-BB90-422B-9EAD-A066D48DE1E8",
              "versionEndExcluding": "1.3.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6501-0001:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DB83620B-3DE0-405A-92F7-99E1B2150E75"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6501-0002_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D2468D0-D50D-4843-8620-CAD0F40E9329",
              "versionEndExcluding": "1.3.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6501-0002:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CC12A2AA-C006-4606-981A-FE54C1EA3B3F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6260-0410_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB404224-29BF-4440-963C-0734A51CE6D1",
              "versionEndExcluding": "1.3.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6260-0410:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0936523A-B9CB-451E-BF5E-9E7020DA96A2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6260-0415_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C17C8F6-8C97-43D5-8ECE-7D9204F3C75D",
              "versionEndExcluding": "1.3.7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:meg6260-0415:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F93C8296-5845-498A-964A-D650F45B27B6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cybersecurity@se.com"
}