First published: Wed Apr 18 2018(Updated: )
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric 140CPU65150 Firmware | ||
Schneider Electric 140CPU65150 Firmware | ||
Schneider Electric 140CPU31110 | ||
Schneider Electric 140CPU31110 | ||
Schneider Electric 140CPU43412U | ||
Schneider Electric 140CPU43412U | ||
Schneider Electric 140CPU65160 Firmware | ||
Schneider Electric 140CPU65160 | ||
Schneider Electric 140CPU65260 Firmware | ||
Schneider Electric 140CPU65260C | ||
Schneider Electric 140CPU65860 | ||
Schneider Electric 140CPU65860 | ||
Schneider Electric 140CPU65160S Firmware | ||
Schneider Electric 140CPU65160S Firmware | ||
Schneider Electric 140CPU65150C Firmware | ||
Schneider Electric 140CPU65150C | ||
Schneider Electric 140CPU31110 | ||
schneider-electric 140cpu31110c | ||
Schneider Electric 140CPU43412UC | ||
Schneider Electric 140CPU43412UC | ||
Schneider Electric 140CPU65160C Firmware | ||
Schneider Electric 140CPU65160C | ||
Schneider Electric 140CPU65260C Firmware | ||
Schneider Electric 140CPU65260C Firmware | ||
Schneider Electric 140CPU65860C Firmware | ||
Schneider Electric 140CPU65860C |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7240 is a vulnerability in Schneider Electric's Modicon Quantum communication modules that allows arbitrary code execution.
CVE-2018-7240 has a severity score of 8.8 out of 10, indicating a high severity vulnerability.
CVE-2018-7240 affects all versions of Schneider Electric's Modicon Quantum communication modules.
CVE-2018-7240 can be exploited by misusing an FTP command used for firmware upgrade to cause a denial of service or load a malicious firmware.
More information about CVE-2018-7240 can be found at the following references: http://www.securityfocus.com/bid/103541, https://ics-cert.us-cert.gov/advisories/ICSA-18-086-01, and https://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/