Medium severity6.5NVD Advisory· Published May 22, 2019· Updated Jun 17, 2026
CVE-2019-6821
CVE-2019-6821
Description
CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when using Ethernet communication in Modicon M580 firmware versions prior to V2.30, and all firmware versions of Modicon M340, Modicon Premium, Modicon Quantum.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:o:schneider-electric:modicon_m340_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m580_firmware:*:*:*:*:*:*:*:*Range: <2.30
cpe:2.3:o:schneider-electric:modicon_premium_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:schneider-electric:modicon_premium_firmware:*:*:*:*:*:*:*:*
- (no CPE)range: all
- cpe:2.3:o:schneider-electric:modicon_quantum_firmware:*:*:*:*:*:*:*:*
- Modicon/M580, M340, Premium, Quantumdescription
- Range: <V2.30
- Range: all
- Range: all
Patches
Vulnerability mechanics
References
3- www.schneider-electric.com/en/download/document/SEVD-2019-134-03/nvdPatchVendor Advisory
- www.securityfocus.com/bid/108366nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-19-136-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.