CWE
287
Advisory Published
Updated

CVE-2018-7760

First published: Wed Apr 18 2018(Updated: )

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization.

Credit: cybersecurity@se.com

Affected SoftwareAffected VersionHow to fix
All of
schneider-electric BMXNOR0200
schneider-electric BMXNOR0200 firmware
All of
Schneider Electric BMXNOR0200H Firmware
Schneider Electric BMXNOR200H
All of
Schneider Electric 140CPU65150 Firmware
Schneider Electric 140CPU65150 Firmware
All of
Schneider Electric 140CPU31110
Schneider Electric 140CPU31110
All of
Schneider Electric 140CPU43412U
Schneider Electric 140CPU43412U
All of
Schneider Electric 140CPU65160 Firmware
Schneider Electric 140CPU65160
All of
Schneider Electric 140CPU65260 Firmware
Schneider Electric 140CPU65260C
All of
Schneider Electric 140CPU65860
Schneider Electric 140CPU65860
All of
Schneider Electric 140CPU65160S Firmware
Schneider Electric 140CPU65160S Firmware
All of
Schneider Electric 140CPU65150C Firmware
Schneider Electric 140CPU65150C
All of
Schneider Electric 140CPU31110
schneider-electric 140cpu31110c
All of
Schneider Electric 140CPU43412UC
Schneider Electric 140CPU43412UC
All of
Schneider Electric 140CPU65160C Firmware
Schneider Electric 140CPU65160C
All of
Schneider Electric 140CPU65260C Firmware
Schneider Electric 140CPU65260C Firmware
All of
Schneider Electric 140CPU65860C Firmware
Schneider Electric 140CPU65860C
All of
Schneider Electric Modicon M340 BMXP341000 Firmware
Schneider Electric Modicon M340 BMXP341000
All of
Schneider Electric Modicon M340 BMXP342000 Firmware
Schneider Electric Modicon M340 BMXP342000 Firmware
All of
Schneider Electric Modicon M340 BMXP3420102 Firmware
Schneider Electric Modicon M340 BMXP3420102
All of
Schneider Electric Modicon M340 BMXP3420102CL Firmware
Schneider Electric Modicon M340 BMXP3420102CL Firmware
All of
Schneider Electric Modicon M340 BMXP342020 Firmware
Schneider Electric Modicon M340 BMXP342020
All of
Schneider Electric Modicon M340 BMXP3420302 Firmware
Schneider Electric Modicon M340 BMXP3420302 Firmware
All of
Schneider Electric Modicon M340 BMXP3420302 Firmware
Schneider Electric Modicon M340 BMXP3420302CL
All of
Schneider Electric Modicon M340 BMXP3420302H Firmware
Schneider Electric Modicon M340 BMXP3420302H Firmware
All of
Schneider Electric Modicon M340 BMXP342020H Firmware
Schneider Electric Modicon M340 BMXP342020H
All of
Schneider Electric Modicon M340 BMXP341000H Firmware
Schneider Electric Modicon M340 BMXP341000H
All of
Schneider Electric TSXH5724M
schneider-electric tsxh5724m firmware
All of
Schneider Electric TSXH5744M Firmware
Schneider Electric TSXH5744M Firmware
All of
Schneider Electric TSXP57104M
Schneider Electric TSXp57104MC
All of
Schneider Electric TSXP57154M Firmware
Schneider Electric TSXP57154M
All of
schneider-electric tsxp571634mc firmware
Schneider Electric TSXP571634M Firmware
All of
Schneider Electric TSXP57204M Firmware
Schneider Electric TSXP57204M
All of
schneider-electric tsxp57254m firmware
schneider-electric tsxp57254m firmware
All of
Schneider Electric TSXP572634M Firmware
Schneider Electric TSXP572634M
All of
Schneider Electric TSXP57304M Firmware
Schneider Electric TSXP57304M Firmware
All of
schneider-electric tsxp57354m firmware
Schneider Electric TSXP57354MC
All of
Schneider Electric TSXP573634M Firmware
Schneider Electric TSXP573634M
All of
Schneider Electric TSXP57454M Firmware
Schneider Electric TSXP57454M
All of
schneider-electric tsxp574634m firmware
Schneider Electric TSXP574634M
All of
schneider-electric tsxp575634m firmware
Schneider Electric TSXP575634M
All of
schneider-electric tsxp576634mc firmware
schneider-electric tsxp576634m firmware
All of
Schneider Electric TSXH5724MC Firmware
Schneider Electric TSXH5724MC
All of
Schneider Electric TSXH5744M Firmware
Schneider Electric TSXH5744MC
All of
Schneider Electric TSXP57104MC Firmware
Schneider Electric TSXP57104MC Firmware
All of
Schneider Electric TSXP57154MC Firmware
Schneider Electric TSXP 57154MC
All of
Schneider Electric TSXP571634M Firmware
Schneider Electric TSXP571634MC
All of
schneider-electric tsxp57204mc firmware
schneider-electric tsxp57204mc firmware
All of
schneider-electric tsxp57254mc firmware
schneider-electric tsxp57254mc firmware
All of
schneider-electric tsxp572634mc firmware
Schneider Electric TSXP572634MC
All of
Schneider Electric TSXP57304MC
schneider-electric tsxp57304mc firmware
All of
Schneider Electric TSXP57354MC
schneider-electric tsxp57354mc firmware
All of
Schneider Electric TSXP573634MC Firmware
Schneider Electric TSXP573634MC
All of
schneider-electric tsxp57454mc firmware
schneider-electric tsxp57454mc firmware
All of
schneider-electric tsxp574634mc firmware
Schneider Electric TSXP574634MC
All of
Schneider Electric TSX P57554M Firmware
Schneider Electric TSXP57554M
All of
schneider-electric tsxp575634mc firmware
schneider-electric tsxp575634mc firmware
All of
schneider-electric tsxp576634mc firmware
schneider-electric tsxp576634mc firmware
All of
Schneider Electric TSX P57554M Firmware
Schneider Electric TSXP57554M
schneider-electric BMXNOR0200
schneider-electric BMXNOR0200 firmware
Schneider Electric BMXNOR0200H Firmware
Schneider Electric BMXNOR200H
Schneider Electric 140CPU65150 Firmware
Schneider Electric 140CPU65150 Firmware
Schneider Electric 140CPU31110
Schneider Electric 140CPU31110
Schneider Electric 140CPU43412U
Schneider Electric 140CPU43412U
Schneider Electric 140CPU65160 Firmware
Schneider Electric 140CPU65160
Schneider Electric 140CPU65260 Firmware
Schneider Electric 140CPU65260C
Schneider Electric 140CPU65860
Schneider Electric 140CPU65860
Schneider Electric 140CPU65160S Firmware
Schneider Electric 140CPU65160S Firmware
Schneider Electric 140CPU65150C Firmware
Schneider Electric 140CPU65150C
Schneider Electric 140CPU31110
schneider-electric 140cpu31110c
Schneider Electric 140CPU43412UC
Schneider Electric 140CPU43412UC
Schneider Electric 140CPU65160C Firmware
Schneider Electric 140CPU65160C
Schneider Electric 140CPU65260C Firmware
Schneider Electric 140CPU65260C Firmware
Schneider Electric 140CPU65860C Firmware
Schneider Electric 140CPU65860C
Schneider Electric BMXP341000 Firmware
Schneider Electric BMXP341000 Firmware
Schneider Electric BMXP342000 Firmware
Schneider Electric BMXP342000 Firmware
Schneider Electric BMXP3420102 Firmware
Schneider Electric BMXP3420102 Firmware
schneider-electric bmxp3420102cl firmware
Schneider Electric BMXP3420102CL
schneider-electric BMXP342020H firmware
schneider-electric BMXP342020H firmware
Schneider Electric BMXP3420302H firmware
Schneider Electric BMXP3420302H firmware
Schneider Electric BMXP3420302CL Firmware
Schneider Electric BMXP3420302CL Firmware
Schneider Electric BMXP3420302H firmware
Schneider Electric BMXP3420302H firmware
schneider-electric BMXP342020H firmware
schneider-electric BMXP342020H firmware
Schneider Electric BMXP341000H Firmware
Schneider Electric BMXP341000H Firmware
Schneider Electric TSXH5724M
schneider-electric tsxh5724m firmware
Schneider Electric TSXH5744M Firmware
Schneider Electric TSXH5744M Firmware
Schneider Electric TSXP57104M
Schneider Electric TSXp57104MC
Schneider Electric TSXP57154M Firmware
Schneider Electric TSXP57154M
schneider-electric tsxp571634mc firmware
Schneider Electric TSXP571634M Firmware
Schneider Electric TSXP57204M Firmware
Schneider Electric TSXP57204M
schneider-electric tsxp57254m firmware
schneider-electric tsxp57254m firmware
Schneider Electric TSXP572634M Firmware
Schneider Electric TSXP572634M
Schneider Electric TSXP57304M Firmware
Schneider Electric TSXP57304M Firmware
schneider-electric tsxp57354m firmware
Schneider Electric TSXP57354MC
Schneider Electric TSXP573634M Firmware
Schneider Electric TSXP573634M
Schneider Electric TSXP57454M Firmware
Schneider Electric TSXP57454M
schneider-electric tsxp574634m firmware
Schneider Electric TSXP574634M
schneider-electric tsxp575634m firmware
Schneider Electric TSXP575634M
schneider-electric tsxp576634mc firmware
schneider-electric tsxp576634m firmware
Schneider Electric TSXH5724MC Firmware
Schneider Electric TSXH5724MC
Schneider Electric TSXH5744M Firmware
Schneider Electric TSXH5744MC
Schneider Electric TSXP57104MC Firmware
Schneider Electric TSXP57104MC Firmware
Schneider Electric TSXP57154MC Firmware
Schneider Electric TSXP 57154MC
Schneider Electric TSXP571634M Firmware
Schneider Electric TSXP571634MC
schneider-electric tsxp57204mc firmware
schneider-electric tsxp57204mc firmware
schneider-electric tsxp57254mc firmware
schneider-electric tsxp57254mc firmware
schneider-electric tsxp572634mc firmware
Schneider Electric TSXP572634MC
Schneider Electric TSXP57304MC
schneider-electric tsxp57304mc firmware
Schneider Electric TSXP57354MC
schneider-electric tsxp57354mc firmware
Schneider Electric TSXP573634MC Firmware
Schneider Electric TSXP573634MC
schneider-electric tsxp57454mc firmware
schneider-electric tsxp57454mc firmware
schneider-electric tsxp574634mc firmware
Schneider Electric TSXP574634MC
Schneider Electric TSX P57554M Firmware
Schneider Electric TSXP57554M
schneider-electric tsxp575634mc firmware
schneider-electric tsxp575634mc firmware
schneider-electric tsxp576634mc firmware
schneider-electric tsxp576634mc firmware
Schneider Electric TSX P57554M Firmware
Schneider Electric TSXP57554M

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2018-7760?

    CVE-2018-7760 has been classified with a high severity rating due to the potential for authorization bypass.

  • How do I fix CVE-2018-7760?

    To remediate CVE-2018-7760, users should update the affected Schneider Electric devices to the latest firmware version that addresses the vulnerability.

  • Which devices are affected by CVE-2018-7760?

    CVE-2018-7760 affects Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, and BMXNOR0200.

  • What type of vulnerability is CVE-2018-7760?

    CVE-2018-7760 is classified as an authorization bypass vulnerability.

  • Can CVE-2018-7760 be exploited remotely?

    Yes, CVE-2018-7760 can be exploited remotely by attackers who send specific requests to the affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203