First published: Wed May 22 2019(Updated: )
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Quantum Firmware | ||
Schneider-electric Modicon Quantum | ||
Schneider-electric Modicon Premium Firmware | ||
Schneider-electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7846 is critical with a score of 9.8.
CVE-2018-7846 is a Trust Boundary Violation vulnerability that allows unauthorized access to the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium controllers through a brute force attack on the Modbus protocol.
All versions of Schneider Electric Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium firmware are affected by CVE-2018-7846.
The CVE-2018-7846 vulnerability can be exploited by conducting a brute force attack on the Modbus protocol to gain unauthorized access to the controllers.
Yes, the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium devices are vulnerable to CVE-2018-7846.