CVE-2018-7240: High severity Schneider-electric 140cpu65150 Firmware vulnerability
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7240?
CVE-2018-7240 is a vulnerability in Schneider Electric's Modicon Quantum communication modules that allows arbitrary code execution.
How severe is CVE-2018-7240?
CVE-2018-7240 has a severity score of 8.8 out of 10, indicating a high severity vulnerability.
Which software versions are affected by CVE-2018-7240?
CVE-2018-7240 affects all versions of Schneider Electric's Modicon Quantum communication modules.
How can CVE-2018-7240 be exploited?
CVE-2018-7240 can be exploited by misusing an FTP command used for firmware upgrade to cause a denial of service or load a malicious firmware.
Where can I find more information about CVE-2018-7240?
More information about CVE-2018-7240 can be found at the following references: http://www.securityfocus.com/bid/103541, https://ics-cert.us-cert.gov/advisories/ICSA-18-086-01, and https://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/