First published: Wed May 22 2019(Updated: )
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M580 Firmware | ||
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-7846 is critical with a score of 9.8.
CVE-2018-7846 is a Trust Boundary Violation vulnerability that allows unauthorized access to the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium controllers through a brute force attack on the Modbus protocol.
All versions of Schneider Electric Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium firmware are affected by CVE-2018-7846.
The CVE-2018-7846 vulnerability can be exploited by conducting a brute force attack on the Modbus protocol to gain unauthorized access to the controllers.
Yes, the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium devices are vulnerable to CVE-2018-7846.