CVE-2019-6852: Schneider Electric 140 CPU6X Firmware

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

Affected products

Published 2019-11-20. Last modified 2026-06-17.