First published: Mon Dec 17 2018(Updated: )
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where an unauthenticated user can send a specially crafted XML data via a POST request to cause the web server to become unavailable
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon BMXNOR0200H Firmware | ||
Schneider Electric Modicon BMXNOR0200H |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7833 is considered high due to the potential for unauthorized access to device functionality.
To fix CVE-2018-7833, update the firmware of affected Modicon devices to the latest version provided by Schneider Electric.
CVE-2018-7833 affects the embedded web servers in all Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 models.
The potential impacts of CVE-2018-7833 include denial of service, where the web server becomes unavailable to users.
Yes, CVE-2018-7833 can be exploited remotely by an unauthenticated user sending a specially crafted XML data via a POST request.