CVE-2018-7804: Medium severity schneider electric modicon m340 firmware vulnerability
Published Dec 17, 2018
·Updated
A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a user clicking on a specially crafted link can be redirected to a URL of the attacker's choosing.
Affected Software
8 affected components
Schneider-electric Modicom M340 Firmware
Schneider-electric Modicom M340
Schneider-electric Modicom Premium Firmware
Schneider-electric Modicom Premium
Schneider-electric Modicom Quantum Firmware
Schneider-electric Modicom Quantum
Schneider-electric Modicom Bmxnor0200h Firmware
Schneider-electric Modicom Bmxnor0200h
Event History
Dec 17, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-7804?
The severity of CVE-2018-7804 is classified as Medium.
2
How do I fix CVE-2018-7804?
To fix CVE-2018-7804, ensure that your firmware is updated to the latest version provided by Schneider Electric.
3
What systems are affected by CVE-2018-7804?
CVE-2018-7804 affects Schneider Electric Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 devices.
4
What does CVE-2018-7804 vulnerability exploit?
CVE-2018-7804 exploits a URL Redirection to Untrusted Site vulnerability.
5
Can CVE-2018-7804 lead to phishing attacks?
Yes, CVE-2018-7804 can lead to phishing attacks by redirecting users to malicious sites.