Vulnerability CVE-2018-7844


Published: 2019-05-22

Description:
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Schneider-electric -> Modicon m340 firmware 
Schneider-electric -> Modicon m580 firmware 
Schneider-electric -> Modicon premium firmware 
Schneider-electric -> Modicon quantum firmware 

 References:
https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/
https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0739

Copyright 2024, cxsecurity.com

 

Back to Top