First published: Wed May 22 2019(Updated: )
A CWE-125: Out-of-bounds Read vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Quantum Firmware | ||
Schneider-electric Modicon Quantum | ||
Schneider-electric Modicon Premium Firmware | ||
Schneider-electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7845 is a vulnerability known as CWE-125: Out-of-bounds Read in Schneider-electric Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium firmware.
The severity of CVE-2018-7845 is high with a severity value of 7.5.
CVE-2018-7845 can lead to the disclosure of unexpected data from the controller when reading specific memory blocks in Schneider-electric Modicon M580 over Modbus.
To fix CVE-2018-7845, it is recommended to apply the necessary security updates provided by Schneider-electric.
You can find more information about CVE-2018-7845 in the following references: - [CVE-2018-7845](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) - [TALOS-2018-0745](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0745)