First published: Wed May 22 2019(Updated: )
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading files from the controller over Modbus
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M580 Firmware | <2.90 | |
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M340 Firmware | <3.10 | |
Schneider Electric Modicon M340 | ||
Schneider Electric Modicon Quantum Firmware | ||
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-7848.
The severity of CVE-2018-7848 is high, with a CVSS score of 7.5.
All versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2018-7848.
CVE-2018-7848 exposes SNMP information when reading files from the controller over Modbus.
You can find more information about CVE-2018-7848 at the following references: [Link 1](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/) and [Link 2](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0740).