First published: Fri Nov 30 2018(Updated: )
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user's browser, potentially impacting the machine the browser is running on.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon BMXNOR0200H Firmware | ||
Schneider Electric Modicon BMXNOR0200H |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7810 has a medium severity, indicating a moderate impact on system security.
To mitigate CVE-2018-7810, it is essential to apply the latest firmware updates from Schneider Electric for affected devices.
CVE-2018-7810 affects Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 embedded web servers.
CVE-2018-7810 is a Cross-site Scripting (XSS) vulnerability that allows the execution of malicious scripts in a user's browser.
Yes, CVE-2018-7810 can be exploited remotely by an attacker crafting a URL containing malicious JavaScript.