CVE-2019-6811

HIGH

Modicon Quantum 140 NOE771x1 Firmware <= 6.9 - Denial of Service via Oversized IP Fragmented Packet

Title source: llm
STIX 2.1

Description

An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-754
Status published
Products (2)
schneider-electric/modicon_quantum_140noe77101_firmware < 6.9
schneider-electric/modicon_quantum_140noe77111_firmware < 6.9
Published Sep 17, 2019
Tracked Since Feb 18, 2026