U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-6833

Change History

Initial Analysis by NIST 9/18/2019 3:29:49 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:h:schneider-electric:hmigtu_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:hmig2u:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmig3u:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmig3ufc:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmig5u:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmig5u2:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmig5ufc:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmig5ul8a:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:hmigto_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:hmigto1300:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto1310:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto2300:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto2310:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto2315:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto3510:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto4310:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto5310:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto5315:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto6310:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigto6315:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:hmigxo_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:hmigxo:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:hmigxu_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:hmigxu35:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmigxu55:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:hmiscu_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:hmiscu6a5:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmiscu6b5:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmiscu8a5:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmiscu8b5:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:hmisto_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:hmisto501:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmisto511:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmisto512:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmisto531:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmisto532:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmisto705:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmisto715:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmisto735:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:hmistu_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:hmistu655:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmistu655w:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmistu855:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:hmistu855w:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:xbtgh_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:xbtgh2460:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:schneider-electric:xbtgt_firmware:-:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:schneider-electric:xbtgt2430:-:*:*:*:*:*:*:*
          cpe:2.3:h:schneider-electric:xbtgt2930:-:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Added CVSS V2 Metadata

								
							
							
						
Victim must voluntarily interact with attack mechanism
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Added CWE

								
							
							
						
CWE-754
Changed Reference Type
https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-225-01 No Types Assigned
https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-225-01 Vendor Advisory