CVE-2019-6859
Estado: ModificadaAlta (7.5)—
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.18%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (10)
Schneider-electric — 140 Cpu6x FirmwareSchneider-electric — 140 NOC 77101 FirmwareSchneider-electric — 140 NOC 78x00 FirmwareSchneider-electric — 140 NOE 771x1 FirmwareSchneider-electric — BMX NOC 0401 FirmwareSchneider-electric — BMX NOE 0100 FirmwareSchneider-electric — BMX NOE 0110 FirmwareSchneider-electric — BMX P34x FirmwareSchneider-electric — TSX ETY X103 FirmwareSchneider-electric — TSX P57x Firmware
CWE
- CWE-798
- CWE-798
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-6859",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cybersecurity@se.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications)",
"versions": [
{
"status": "affected",
"version": "Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security notifications)"
}
]
}
]
}
],
"published": "2020-04-22T19:15:11.573",
"references": [
{
"url": "https://www.se.com/ww/en/download/document/SEVD-2019-316-02",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@se.com"
},
{
"url": "https://www.se.com/ww/en/download/document/SEVD-2019-316-02",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@se.com",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network."
},
{
"lang": "es",
"value": "A CWE-798: Existe una vulnerabilidad de Uso de Credenciales Embebidas en los controladores Modicon (todas las versiones de las siguientes referencias de productos de CPU y módulo de comunicación enumeradas en las Notificaciones de Seguridad), lo que podría causar una divulgación de credenciales embebidas FTP cuando se usa el servidor Web del controlador en una red no segura"
}
],
"lastModified": "2026-06-17T02:39:48.963",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:bmx_p34x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14850FBA-6534-47DB-963A-9D1973CD743E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:bmx_p34x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "31641D9C-5A26-4632-AF77-DF0596027EBF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:bmx_noe_0100_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "357C2EC3-AF99-4C28-9F25-7535B6279039"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:bmx_noe_0100:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2E25BD42-AEA0-4834-8EF6-A030F34F3C0E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:bmx_noe_0110_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "245BC693-0C80-433D-B966-7EEC40BDF4B2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:bmx_noe_0110:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8F06E131-2AAE-4A34-AA96-A4828C01E9FB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:bmx_noc_0401_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A897B7E-4CBC-48F5-BAF0-D127A73E287C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:bmx_noc_0401:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "790F8548-142B-4F0E-9A1E-B4570DA76917"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tsx_p57x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0194B54A-6A29-4539-8BD3-0A0CCC04DB59"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tsx_p57x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1556D664-D4CF-4B0E-A2AD-262B511F1FBF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tsx_ety_x103_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B550F75-2542-4DED-A588-3D7783652B8D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tsx_ety_x103:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E63E90D7-795C-4B98-91D5-BD11DCA34AFA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:140_cpu6x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C678406-4896-4209-B75C-49D4A946DBF1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:140_cpu6x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BF08312C-4614-4FE1-AE24-21E1F6E6D3BF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:140_noe_771x1_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6090B04C-F4C2-4261-896A-F70019DCD5BC"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:140_noe_771x1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "22AB350E-16AF-433A-A4B6-409DE325B63D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:140_noc_78x00_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B735DC2-F3B6-4F16-9747-665466B43EC6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:140_noc_78x00:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "65ED8C96-0B54-4BB6-BFD6-71D54905C517"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:140_noc_77101_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6EDC7834-486B-4B72-A18D-C6B900F7D090"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:140_noc_77101:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E7F4A0D3-FD4D-47E9-B4A6-C78348464907"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cybersecurity@se.com"
}