CVE-2019-6828 is an uncaught-exception flaw in Schneider Electric Modicon controllers that can cause a denial of service when specific coils and registers are read over Modbus. The CISA/Schneider advisory published on 2019-05-14 covers multiple product lines, including M580, M340, Quantum, and Premium, with firmware fixes and network-hardening mitigations.
CVE-2019-6809 is a high-severity denial-of-service issue in Schneider Electric Modicon controllers. According to the advisory, reading invalid data from the controller can trigger an uncaught exception, which may disrupt availability. The vendor and CISA guidance tie remediation to firmware updates and OT network hardening measures, especially for systems that expose Modbus/TCP or other controller access paths.