CVE-2023-6408
HIGHDescription
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| schneider-electric | modicon_m340_bmxp341000_firmware |
| schneider-electric | modicon_m340_bmxp341000 |
| schneider-electric | modicon_m340_bmxp341000h_firmware |
| schneider-electric | modicon_m340_bmxp341000h |
| schneider-electric | modicon_m340_bmxp342000_firmware |
| schneider-electric | modicon_m340_bmxp342000 |
| schneider-electric | modicon_m340_bmxp342010_firmware |
| schneider-electric | modicon_m340_bmxp342010 |
| schneider-electric | modicon_m340_bmxp3420102_firmware |
| schneider-electric | modicon_m340_bmxp3420102 |
| schneider-electric | modicon_m340_bmxp3420102cl_firmware |
| schneider-electric | modicon_m340_bmxp3420102cl |
| schneider-electric | modicon_m340_bmxp342020_firmware |
| schneider-electric | modicon_m340_bmxp342020 |
| schneider-electric | modicon_m340_bmxp342020h_firmware |
| schneider-electric | modicon_m340_bmxp342020h |
| schneider-electric | modicon_m340_bmxp342030_firmware |
| schneider-electric | modicon_m340_bmxp342030 |
| schneider-electric | modicon_m340_bmxp3420302_firmware |
| schneider-electric | modicon_m340_bmxp3420302 |
| schneider-electric | modicon_m340_bmxp3420302cl_firmware |
| schneider-electric | modicon_m340_bmxp3420302cl |
| schneider-electric | modicon_m340_bmxp3420302h_firmware |
| schneider-electric | modicon_m340_bmxp3420302h |
| schneider-electric | modicon_m340_bmxp342030h_firmware |
| schneider-electric | modicon_m340_bmxp342030h |
| schneider-electric | modicon_m580_bmep581020_firmware |
| schneider-electric | modicon_m580_bmep581020 |
| schneider-electric | modicon_m580_bmep581020h_firmware |
| schneider-electric | modicon_m580_bmep581020h |
| schneider-electric | modicon_m580_bmep582020_firmware |
| schneider-electric | modicon_m580_bmep582020 |
| schneider-electric | modicon_m580_bmep582020h_firmware |
| schneider-electric | modicon_m580_bmep582020h |
| schneider-electric | modicon_m580_bmep582040_firmware |
| schneider-electric | modicon_m580_bmep582040 |
| schneider-electric | modicon_m580_bmep582040h_firmware |
| schneider-electric | modicon_m580_bmep582040h |
| schneider-electric | modicon_m580_bmep582040s_firmware |
| schneider-electric | modicon_m580_bmep582040s |
| schneider-electric | modicon_m580_bmep583020_firmware |
| schneider-electric | modicon_m580_bmep583020 |
| schneider-electric | modicon_m580_bmep583040_firmware |
| schneider-electric | modicon_m580_bmep583040 |
| schneider-electric | modicon_m580_bmep584040_firmware |
| schneider-electric | modicon_m580_bmep584040 |
| schneider-electric | modicon_m580_bmep584020_firmware |
| schneider-electric | modicon_m580_bmep584020 |
| schneider-electric | modicon_m580_bmep584040s_firmware |
| schneider-electric | modicon_m580_bmep584040s |
| schneider-electric | modicon_m580_bmep585040_firmware |
| schneider-electric | modicon_m580_bmep585040 |
| schneider-electric | modicon_m580_bmep585040c_firmware |
| schneider-electric | modicon_m580_bmep585040c |
| schneider-electric | modicon_m580_bmep586040_firmware |
| schneider-electric | modicon_m580_bmep586040 |
| schneider-electric | modicon_m580_bmep586040c_firmware |
| schneider-electric | modicon_m580_bmep586040c |
| schneider-electric | modicon_m580_bmeh582040_firmware |
| schneider-electric | modicon_m580_bmeh582040 |
| schneider-electric | modicon_m580_bmeh582040c_firmware |
| schneider-electric | modicon_m580_bmeh582040c |
| schneider-electric | modicon_m580_bmeh584040_firmware |
| schneider-electric | modicon_m580_bmeh584040 |
| schneider-electric | modicon_m580_bmeh582040s_firmware |
| schneider-electric | modicon_m580_bmeh582040s |
| schneider-electric | modicon_m580_bmeh584040c_firmware |
| schneider-electric | modicon_m580_bmeh584040c |
| schneider-electric | modicon_m580_bmeh584040s_firmware |
| schneider-electric | modicon_m580_bmeh584040s |
| schneider-electric | modicon_m580_bmeh586040_firmware |
| schneider-electric | modicon_m580_bmeh586040 |
| schneider-electric | modicon_m580_bmeh586040c_firmware |
| schneider-electric | modicon_m580_bmeh586040c |
| schneider-electric | modicon_m580_bmeh586040s_firmware |
| schneider-electric | modicon_m580_bmeh586040s |
| schneider-electric | modicon_mc80_bmkc8020301_firmware |
| schneider-electric | modicon_mc80_bmkc8020301 |
| schneider-electric | modicon_mc80_bmkc8020310_firmware |
| schneider-electric | modicon_mc80_bmkc8020310 |
| schneider-electric | modicon_mc80_bmkc8030311 |
| schneider-electric | modicon_mc80_bmkc8030311_firmware |
| schneider-electric | modicon_momentum_171cbu78090_firmware |
| schneider-electric | modicon_momentum_171cbu78090 |
| schneider-electric | modicon_momentum_171cbu98090_firmware |
| schneider-electric | modicon_momentum_171cbu98090 |
| schneider-electric | modicon_momentum_171cbu98091_firmware |
| schneider-electric | modicon_momentum_171cbu98091 |
| schneider-electric | ecostruxure_control_expert |
| schneider-electric | ecostruxure_process_expert |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-6408? +
How severe is CVE-2023-6408? +
What products are affected by CVE-2023-6408? +
How do I check if I'm vulnerable to CVE-2023-6408? +
Related Vulnerabilities
A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before …
Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an …
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response …
The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and …
An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each …
Windows DNS Spoofing Vulnerability