First published: Wed May 22 2019(Updated: )
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | ||
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | ||
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Quantum Firmware | ||
Schneider-electric Modicon Quantum | ||
Schneider-electric Modicon Premium Firmware | ||
Schneider-electric Modicon Premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7852 is a vulnerability known as Uncaught Exception vulnerability that exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium.
The severity of CVE-2018-7852 is high with a CVSS score of 7.5.
CVE-2018-7852 affects the Modicon M580 Firmware, Modicon M340 Firmware, Modicon Quantum Firmware, and Modicon Premium Firmware.
CVE-2018-7852 can be exploited by sending an invalid private command parameter to the controller over Modbus, causing a denial of service.
Yes, all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium are vulnerable to CVE-2018-7852.