URL Redirection Vulnerability in Modicon PLCs by Schneider Electric
CVE-2018-7804

6.1MEDIUM

Key Information:

Summary

A vulnerability affecting Schneider Electric's Modicon PLCs, including M340, Premium, Quantum models, and BMXNOR0200, allows attackers to redirect users to untrusted URLs via maliciously crafted links. This redirection can lead to phishing attacks and expose sensitive information, making it essential for users to be aware of the risks and implement necessary security measures to mitigate potential threats.

Affected Version(s)

Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.