CVE-2018-7811: Critical severity schneider electric modicon m340 firmware vulnerability
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7811?
CVE-2018-7811 is classified as a high severity vulnerability due to the potential for unauthorized access to the password change function.
How do I fix CVE-2018-7811?
To mitigate CVE-2018-7811, ensure web server access is restricted to authorized users only and apply necessary firmware updates as they become available.
What devices are affected by CVE-2018-7811?
CVE-2018-7811 affects the embedded web servers in Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 devices.
Can CVE-2018-7811 be exploited remotely?
Yes, CVE-2018-7811 can be exploited by an unauthenticated remote user to access the change password function.
Is there a workaround for CVE-2018-7811?
A recommended workaround for CVE-2018-7811 is to limit network access to the affected devices by using firewalls or VPNs.