First published: Wed May 22 2019(Updated: )
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Quantum Firmware | ||
Schneider-electric Modicon Quantum | ||
Schneider-electric Modicon Premium Firmware | ||
Schneider-electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7843 is high with a severity value of 7.5.
All versions of Schneider-electric Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2018-7843.
CVE-2018-7843 is a CWE-248: Uncaught Exception vulnerability that can cause denial of service when reading memory blocks with an invalid data size or offset in the controller over Modbus.
Schneider-electric has released a security advisory with recommendations on mitigating the vulnerability. Please refer to their advisory for the appropriate fixes.
For more information about CVE-2018-7843, you can refer to the Schneider-electric security advisory and the Talos Intelligence vulnerability report linked in the references.