First published: Wed May 22 2019(Updated: )
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon Premium Firmware | ||
Schneider-electric Modicon Premium | ||
Schneider-electric Modicon Quantum Firmware | ||
Schneider-electric Modicon Quantum | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this information exposure vulnerability is CVE-2018-7844.
CVE-2018-7844 has a severity rating of 7.5 (high).
All versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2018-7844.
CVE-2018-7844 discloses SNMP information when reading memory blocks from the controller over Modbus.
You can find more information about CVE-2018-7844 at the following references: [link1](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) and [link2](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0739).