First published: Mon Dec 17 2018(Updated: )
An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon BMXNOR0200H Firmware | ||
Schneider Electric Modicon BMXNOR0200H |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7812 is classified as a medium severity vulnerability due to potential information exposure.
To mitigate CVE-2018-7812, upgrade the affected embedded web server firmware to the latest version provided by Schneider Electric.
CVE-2018-7812 affects Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 with specific embedded web server firmware versions.
CVE-2018-7812 is an Information Exposure through Discrepancy vulnerability in embedded web servers.
CVE-2018-7812 may expose security-relevant information about the operational state of the affected products.