PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-6809 Schneider Electric SE CVE debrief

CVE-2019-6809 is a high-severity denial-of-service issue in Schneider Electric Modicon controllers. According to the advisory, reading invalid data from the controller can trigger an uncaught exception, which may disrupt availability. The vendor and CISA guidance tie remediation to firmware updates and OT network hardening measures, especially for systems that expose Modbus/TCP or other controller access paths.

Vendor
Schneider Electric SE
Product
Modicon M580 Controller
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2019-05-14
Original CVE updated
2026-04-23
Advisory published
2019-05-14
Advisory updated
2026-04-23

Who should care

OT and ICS teams running Schneider Electric Modicon M580, M340, Quantum, or Premium controllers; engineers using EcoStruxure Control Expert; plant operators responsible for availability-critical automation networks; and defenders who must protect controller access over port 502/TCP.

Technical summary

The source advisory describes an uncaught exception condition that can be triggered when invalid data is read from the controller, resulting in a possible denial of service. The published CVSS 3.1 metadata indicates network attackability, low complexity, no privileges, no user interaction, and availability impact only (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, score 7.5 High). The advisory text also includes a CVSS v4.0 base score of 8.7 High. Affected products include Modicon M580 firmware prior to v2.90, Modicon M340 firmware prior to v3.10, listed Modicon Quantum firmware versions prior to v3.60, and Modicon Premium firmware prior to v3.20, with multiple remediation notes for EOL Quantum and Premium platforms.

Defensive priority

High. Prioritize if the affected controllers are reachable from broader OT or enterprise networks, especially where Modbus/TCP access is present. Treat as urgent in environments where controller availability is critical and patching or segmentation is incomplete.

Recommended defensive actions

  • Inventory Schneider Electric controllers and confirm whether any affected firmware versions are deployed.
  • Upgrade Modicon M580 to firmware SV4.20 or above and update EcoStruxure Control Expert as instructed by Schneider Electric.
  • Upgrade Modicon M340 to firmware v3.60 or above and update EcoStruxure Control Expert as instructed by Schneider Electric.
  • For affected Quantum and Premium systems, apply the vendor's remediation guidance and plan migration where products are end of life.
  • Restrict access to controller services by applying network segmentation, firewall controls, and ACLs to block unauthorized access to port 502/TCP.
  • Enable application passwords and follow the secured communications guidance referenced in the vendor materials.
  • For M580/M340 architectures, use the vendor-recommended secure communication options, including IPsec where applicable, and verify controller memory protection guidance for supported configurations.

Evidence notes

Primary evidence comes from the CISA CSAF advisory ICSA-25-114-01 and the Schneider Electric Security and Safety Notice SEVD-2019-134-11. The advisory states that an uncaught exception can cause denial of service when invalid data is read from the controller. The source includes version-specific fixes and mitigation guidance, plus later revision history entries that expand remediation and hardening instructions. The supplied source metadata also contains both CVSS 3.1 and CVSS v4.0 scores; the debrief preserves that distinction rather than treating either as the only score.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-6809 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-6809

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-6809 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-6809

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-114-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/ww/en/download/document/7EN52-0390/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.