PatchSiren

Schneider Electric SE CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Schneider Electric SE CVE published 2019-05-14

CVE-2019-6828

CVE-2019-6828 is an uncaught-exception flaw in Schneider Electric Modicon controllers that can cause a denial of service when specific coils and registers are read over Modbus. The CISA/Schneider advisory published on 2019-05-14 covers multiple product lines, including M580, M340, Quantum, and Premium, with firmware fixes and network-hardening mitigations.

HIGH Schneider Electric SE CVE published 2019-05-14

CVE-2019-6809

CVE-2019-6809 is a high-severity denial-of-service issue in Schneider Electric Modicon controllers. According to the advisory, reading invalid data from the controller can trigger an uncaught exception, which may disrupt availability. The vendor and CISA guidance tie remediation to firmware updates and OT network hardening measures, especially for systems that expose Modbus/TCP or other controller access paths.