Vulnerability Details CVE-2019-6833
A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2019-6833
-
cpe:2.3:h:schneider-electric:hmig2u:-
-
cpe:2.3:h:schneider-electric:hmig3u:-
-
cpe:2.3:h:schneider-electric:hmig3ufc:-
-
cpe:2.3:h:schneider-electric:hmig5u2:-
-
cpe:2.3:h:schneider-electric:hmig5u:-
-
cpe:2.3:h:schneider-electric:hmig5ufc:-
-
cpe:2.3:h:schneider-electric:hmig5ul8a:-
-
cpe:2.3:h:schneider-electric:hmigto1300:-
-
cpe:2.3:h:schneider-electric:hmigto1310:-
-
cpe:2.3:h:schneider-electric:hmigto2300:-
-
cpe:2.3:h:schneider-electric:hmigto2310:-
-
cpe:2.3:h:schneider-electric:hmigto2315:-
-
cpe:2.3:h:schneider-electric:hmigto3510:-
-
cpe:2.3:h:schneider-electric:hmigto4310:-
-
cpe:2.3:h:schneider-electric:hmigto5310:-
-
cpe:2.3:h:schneider-electric:hmigto5315:-
-
cpe:2.3:h:schneider-electric:hmigto6310:-
-
cpe:2.3:h:schneider-electric:hmigto6315:-
-
cpe:2.3:h:schneider-electric:hmigtu_firmware:-
-
cpe:2.3:h:schneider-electric:hmigxo:-
-
cpe:2.3:h:schneider-electric:hmigxu35:-
-
cpe:2.3:h:schneider-electric:hmigxu55:-
-
cpe:2.3:h:schneider-electric:hmiscu6a5:-
-
cpe:2.3:h:schneider-electric:hmiscu6b5:-
-
cpe:2.3:h:schneider-electric:hmiscu8a5:-
-
cpe:2.3:h:schneider-electric:hmiscu8b5:-
-
cpe:2.3:h:schneider-electric:hmisto501:-
-
cpe:2.3:h:schneider-electric:hmisto511:-
-
cpe:2.3:h:schneider-electric:hmisto512:-
-
cpe:2.3:h:schneider-electric:hmisto531:-
-
cpe:2.3:h:schneider-electric:hmisto532:-
-
cpe:2.3:h:schneider-electric:hmisto705:-
-
cpe:2.3:h:schneider-electric:hmisto715:-
-
cpe:2.3:h:schneider-electric:hmisto735:-
-
cpe:2.3:h:schneider-electric:hmistu655:-
-
cpe:2.3:h:schneider-electric:hmistu655w:-
-
cpe:2.3:h:schneider-electric:hmistu855:-
-
cpe:2.3:h:schneider-electric:hmistu855w:-
-
cpe:2.3:h:schneider-electric:xbtgh2460:-
-
cpe:2.3:h:schneider-electric:xbtgt2430:-
-
cpe:2.3:h:schneider-electric:xbtgt2930:-
-
cpe:2.3:o:schneider-electric:hmigto_firmware:-
-
cpe:2.3:o:schneider-electric:hmigxo_firmware:-
-
cpe:2.3:o:schneider-electric:hmigxu_firmware:-
-
cpe:2.3:o:schneider-electric:hmiscu_firmware:-
-
cpe:2.3:o:schneider-electric:hmisto_firmware:-
-
cpe:2.3:o:schneider-electric:hmistu_firmware:-
-
cpe:2.3:o:schneider-electric:xbtgh_firmware:-
-
cpe:2.3:o:schneider-electric:xbtgt_firmware:-