CVE-2018-7855: High severity modicon premium firmware vulnerability
A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a Denial of Service when sending invalid breakpoint parameters to the controller over Modbus
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7855?
CVE-2018-7855 is a vulnerability titled 'A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium' which could cause a Denial of Service when sending invalid breakpoint parameters to the controller over Modbus.
Which software versions are affected by CVE-2018-7855?
CVE-2018-7855 affects all versions of Schneider-electric Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium.
What is the severity of CVE-2018-7855?
CVE-2018-7855 has a severity rating of 7.5, which is classified as high.
How can CVE-2018-7855 be exploited?
CVE-2018-7855 can be exploited by sending invalid breakpoint parameters to the affected Modicon controllers over Modbus, leading to a Denial of Service condition.
Are there any references for CVE-2018-7855?
Yes, you can find more information about CVE-2018-7855 at the following references: [Reference 1](https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/), [Reference 2](https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0766), [Reference 3](https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0767).