CVE-2018-7830: High severity schneider electric modicon m340 firmware vulnerability
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7830?
CVE-2018-7830 has a medium severity level due to its potential to cause a denial of service.
How do I fix CVE-2018-7830?
To fix CVE-2018-7830, apply the latest firmware updates provided by Schneider Electric for affected Modicon PLC models.
What devices are affected by CVE-2018-7830?
CVE-2018-7830 affects all Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 embedded web servers.
What happens if CVE-2018-7830 is exploited?
Exploiting CVE-2018-7830 can lead to a denial of service condition lasting approximately one minute.
Is CVE-2018-7830 a widespread vulnerability?
Yes, CVE-2018-7830 is a notable vulnerability affecting multiple models of Schneider Electric's Modicon PLCs.