CVE-2018-7844: Infoleak
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this information exposure vulnerability?
The vulnerability ID for this information exposure vulnerability is CVE-2018-7844.
What is the severity rating of CVE-2018-7844?
CVE-2018-7844 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2018-7844?
All versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2018-7844.
How does CVE-2018-7844 disclose SNMP information?
CVE-2018-7844 discloses SNMP information when reading memory blocks from the controller over Modbus.
How can I find more information about CVE-2018-7844?
You can find more information about CVE-2018-7844 at the following references: [link1](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) and [link2](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0739).