CVE-2018-7842: Critical severity schneider electric modicon m580 firmware vulnerability
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7842?
CVE-2018-7842 is a CWE-290: Authentication Bypass by Spoofing vulnerability that exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium.
How does CVE-2018-7842 impact Schneider-electric Modicon M580 Firmware?
CVE-2018-7842 can cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
What is the severity of CVE-2018-7842?
CVE-2018-7842 has a severity rating of 9.8 (critical).
How can I fix CVE-2018-7842?
To mitigate CVE-2018-7842, apply the recommended security patches provided by Schneider Electric and follow the guidelines mentioned in their advisory.
Where can I find more information about CVE-2018-7842?
You can find more information about CVE-2018-7842 in the Schneider Electric security advisory (SEVD-2019-134-11) and the Talos Intelligence vulnerability report (TALOS-2018-0741).