First published: Wed May 22 2019(Updated: )
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M580 Firmware | ||
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7843 is high with a severity value of 7.5.
All versions of Schneider-electric Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2018-7843.
CVE-2018-7843 is a CWE-248: Uncaught Exception vulnerability that can cause denial of service when reading memory blocks with an invalid data size or offset in the controller over Modbus.
Schneider-electric has released a security advisory with recommendations on mitigating the vulnerability. Please refer to their advisory for the appropriate fixes.
For more information about CVE-2018-7843, you can refer to the Schneider-electric security advisory and the Talos Intelligence vulnerability report linked in the references.