First published: Mon Dec 17 2018(Updated: )
A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a user clicking on a specially crafted link can be redirected to a URL of the attacker's choosing.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon BMXNOR0200H Firmware | ||
Schneider Electric Modicon BMXNOR0200H |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7804 is classified as Medium.
To fix CVE-2018-7804, ensure that your firmware is updated to the latest version provided by Schneider Electric.
CVE-2018-7804 affects Schneider Electric Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 devices.
CVE-2018-7804 exploits a URL Redirection to Untrusted Site vulnerability.
Yes, CVE-2018-7804 can lead to phishing attacks by redirecting users to malicious sites.