First published: Wed May 22 2019(Updated: )
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible Denial of Service when writing out of bounds variables to the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon Premium | <3.20 | |
Schneider Electric Modicon Premium | ||
Schneider Electric Modicon Quantum Firmware | <3.60 | |
Schneider Electric Modicon Quantum | ||
Schneider Electric Modicon M340 Firmware | <3.01 | |
Schneider Electric Modicon M340 | ||
Schneider Electric Modicon M580 Firmware | <2.80 | |
Schneider Electric Modicon M580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7857 is a vulnerability that exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible Denial of Service when writing out of bounds variables to the controller over Modbus.
CVE-2018-7857 affects all versions of Schneider-electric Modicon Premium Firmware up to version 3.20, Modicon Quantum Firmware up to version 3.60, Modicon M340 Firmware up to version 3.01, and Modicon M580 Firmware up to version 2.80.
CVE-2018-7857 has a severity rating of 7.5 (high).
CVE-2018-7857 can be exploited by writing out of bounds variables to the controller over Modbus.
To fix CVE-2018-7857, update the affected products to the latest firmware version provided by Schneider-electric.