First published: Wed May 22 2019(Updated: )
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible Denial of Service when writing out of bounds variables to the controller over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon Premium Firmware | <3.20 | |
Schneider-electric Modicon Premium | ||
Schneider-electric Modicon Quantum Firmware | <3.60 | |
Schneider-electric Modicon Quantum | ||
Schneider-electric Modicon M340 Firmware | <3.01 | |
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon M580 Firmware | <2.80 | |
Schneider-electric Modicon M580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7857 is a vulnerability that exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible Denial of Service when writing out of bounds variables to the controller over Modbus.
CVE-2018-7857 affects all versions of Schneider-electric Modicon Premium Firmware up to version 3.20, Modicon Quantum Firmware up to version 3.60, Modicon M340 Firmware up to version 3.01, and Modicon M580 Firmware up to version 2.80.
CVE-2018-7857 has a severity rating of 7.5 (high).
CVE-2018-7857 can be exploited by writing out of bounds variables to the controller over Modbus.
To fix CVE-2018-7857, update the affected products to the latest firmware version provided by Schneider-electric.