CVE-2018-7812: Infoleak
An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7812?
CVE-2018-7812 is classified as a medium severity vulnerability due to potential information exposure.
How do I fix CVE-2018-7812?
To mitigate CVE-2018-7812, upgrade the affected embedded web server firmware to the latest version provided by Schneider Electric.
What products are affected by CVE-2018-7812?
CVE-2018-7812 affects Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 with specific embedded web server firmware versions.
What type of vulnerability is CVE-2018-7812?
CVE-2018-7812 is an Information Exposure through Discrepancy vulnerability in embedded web servers.
What kind of information may be exposed due to CVE-2018-7812?
CVE-2018-7812 may expose security-relevant information about the operational state of the affected products.