URL Redirection Vulnerability in Modicon PLCs by Schneider Electric
CVE-2018-7804
6.1MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 17 December 2018
Summary
A vulnerability affecting Schneider Electric's Modicon PLCs, including M340, Premium, Quantum models, and BMXNOR0200, allows attackers to redirect users to untrusted URLs via maliciously crafted links. This redirection can lead to phishing attacks and expose sensitive information, making it essential for users to be aware of the risks and implement necessary security measures to mitigate potential threats.
Affected Version(s)
Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved