Unverified Password Change in Modicon PLCs and BMXNOR0200 by Schneider Electric
CVE-2018-7809
9.8CRITICAL
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 30 November 2018
What is CVE-2018-7809?
An unverified password change vulnerability exists in the embedded web servers of Modicon M340, Premium, Quantum PLCs, and BMXNOR0200. This weakness could allow an unauthenticated remote user to access critical password management functions, potentially leading to unauthorized control over system configurations. Organizations utilizing these products must take immediate action to mitigate risks associated with this vulnerability.
Affected Version(s)
Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200