High severity7.5NVD Advisory· Published Apr 22, 2020· Updated Jun 17, 2026
CVE-2019-6859
CVE-2019-6859
Description
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
Affected products
12- cpe:2.3:o:schneider-electric:140_cpu6x_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:140_noc_77101_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:140_noc_78x00_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:140_noe_771x1_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:bmx_noc_0401_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:bmx_noe_0100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:bmx_noe_0110_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:bmx_p34x_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:tsx_ety_x103_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:tsx_p57x_firmware:*:*:*:*:*:*:*:*
- Schneider Electric/Modicon Controllersdescription
- Range: All versions
Patches
Vulnerability mechanics
References
1- www.se.com/ww/en/download/document/SEVD-2019-316-02nvdVendor Advisory
News mentions
0No linked articles in our index yet.