CVE-2018-7833: High severity schneider electric modicon m340 firmware vulnerability
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where an unauthenticated user can send a specially crafted XML data via a POST request to cause the web server to become unavailable
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7833?
The severity of CVE-2018-7833 is considered high due to the potential for unauthorized access to device functionality.
How do I fix CVE-2018-7833?
To fix CVE-2018-7833, update the firmware of affected Modicon devices to the latest version provided by Schneider Electric.
Who is affected by CVE-2018-7833?
CVE-2018-7833 affects the embedded web servers in all Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 models.
What are the potential impacts of CVE-2018-7833?
The potential impacts of CVE-2018-7833 include denial of service, where the web server becomes unavailable to users.
Can CVE-2018-7833 be exploited remotely?
Yes, CVE-2018-7833 can be exploited remotely by an unauthenticated user sending a specially crafted XML data via a POST request.