CVE-2018-7849: High severity schneider electric modicon m580 firmware vulnerability
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause a possible Denial of Service due to improper data integrity check when sending files the controller over Modbus.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-7849.
What is the severity of CVE-2018-7849?
The severity of CVE-2018-7849 is high with a severity value of 7.5.
Which software is affected by CVE-2018-7849?
All versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are affected by CVE-2018-7849.
How does CVE-2018-7849 impact the affected software?
CVE-2018-7849 could cause a possible Denial of Service due to improper data integrity check when sending files to the controller over Modbus.
Is there a fix available for CVE-2018-7849?
To fix CVE-2018-7849, it is recommended to refer to the vendor's advisory and apply any patches or updates as provided.