CVE-2018-7838: Buffer Overflow
A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7838?
CVE-2018-7838 is a Buffer Errors vulnerability that exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16.
What is the severity of CVE-2018-7838?
CVE-2018-7838 has a severity keyword of high and a severity value of 7.5.
How does CVE-2018-7838 affect Schneider-electric Bmenoc0301 firmware?
CVE-2018-7838 affects Schneider-electric Bmenoc0301 firmware versions up to but excluding V2.16.
How does CVE-2018-7838 affect Schneider-electric Modicon M580 Bmep582040 firmware?
CVE-2018-7838 affects Schneider-electric Modicon M580 Bmep582040 firmware versions up to but excluding V2.90.
How do I fix CVE-2018-7838?
To fix CVE-2018-7838, update to Modicon M580 CPU - BMEP582040 firmware version V2.90 or later, and Modicon Ethernet Module BMENOC0301 firmware version V2.16 or later.