CVE-2019-6833

A

CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:hmigto_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:hmigto1300:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto1310:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto2300:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto2310:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto2315:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto3510:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto4310:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto5310:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto5315:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto6310:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigto6315:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:hmisto_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:hmisto501:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmisto511:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmisto512:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmisto531:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmisto532:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmisto705:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmisto715:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmisto735:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:xbtgh_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:xbtgh2460:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:schneider-electric:hmigtu_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:hmig2u:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmig3u:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmig3ufc:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmig5u:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmig5u2:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmig5ufc:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmig5ul8a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:hmiscu_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:hmiscu6a5:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmiscu6b5:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmiscu8a5:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmiscu8b5:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:hmistu_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:hmistu655:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmistu655w:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmistu855:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmistu855w:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:schneider-electric:xbtgt_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:xbtgt2430:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:xbtgt2930:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:schneider-electric:hmigxo_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigxo:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:schneider-electric:hmigxu_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:hmigxu35:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:hmigxu55:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:47

Type Values Removed Values Added
References () https://security.cse.iitk.ac.in/responsible-disclosure - () https://security.cse.iitk.ac.in/responsible-disclosure -
References () https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-225-01 - Vendor Advisory () https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-225-01 - Vendor Advisory