CVE-2018-7847: Critical severity schneider electric modicon m580 firmware vulnerability
Published May 22, 2019
·Updated
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
Affected Software
8 affected components
Schneider-electric Modicon M580 Firmware
Schneider-electric Modicon M580
Schneider-electric Modicon M340 Firmware
Schneider-electric Modicon M340
Schneider-electric Modicon Quantum Firmware
Schneider-electric Modicon Quantum
Schneider-electric Modicon Premium Firmware
Schneider-electric Modicon Premium
Event History
May 22, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-7847.
2
What is the severity of CVE-2018-7847?
The severity of CVE-2018-7847 is critical.
3
Which versions of Modicon M580 are affected by CVE-2018-7847?
All versions of Modicon M580 are affected by CVE-2018-7847.
4
What is the impact of CVE-2018-7847?
CVE-2018-7847 could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
5
Are there any fixes available for CVE-2018-7847?
Please refer to the reference links provided for information on available fixes for CVE-2018-7847.