CVE-2018-7846: Critical severity schneider electric modicon m580 firmware vulnerability
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7846?
The severity of CVE-2018-7846 is critical with a score of 9.8.
What is the description of CVE-2018-7846?
CVE-2018-7846 is a Trust Boundary Violation vulnerability that allows unauthorized access to the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium controllers through a brute force attack on the Modbus protocol.
Which software versions are affected by CVE-2018-7846?
All versions of Schneider Electric Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium firmware are affected by CVE-2018-7846.
How can the CVE-2018-7846 vulnerability be exploited?
The CVE-2018-7846 vulnerability can be exploited by conducting a brute force attack on the Modbus protocol to gain unauthorized access to the controllers.
Are the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium devices vulnerable to CVE-2018-7846?
Yes, the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium devices are vulnerable to CVE-2018-7846.