CVE-2018-7848: Infoleak
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading files from the controller over Modbus
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-7848.
What is the severity of CVE-2018-7848?
The severity of CVE-2018-7848 is high, with a CVSS score of 7.5.
Which software versions are affected by CVE-2018-7848?
All versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2018-7848.
How does CVE-2018-7848 expose information?
CVE-2018-7848 exposes SNMP information when reading files from the controller over Modbus.
Where can I find more information about CVE-2018-7848?
You can find more information about CVE-2018-7848 at the following references: [Link 1](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) and [Link 2](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0740).