Buffer Errors Vulnerability in Schneider Electric Modicon Products
CVE-2018-7851

6.5MEDIUM

Summary

A buffer errors vulnerability exists in Schneider Electric's Modicon products, specifically affecting Modicon M580 with firmware versions prior to V2.50, Modicon M340 with firmware versions prior to V3.01, and the BMxCRA312xx series with firmware prior to V2.40. Additionally, all firmware versions of Modicon Premium and 140CRA312xxx are impacted. When these devices receive a specially crafted Modbus packet, they may experience a denial of service conditions, causing the devices to restart to restore functionality. This vulnerability poses a risk to device availability and operational continuity.

Affected Version(s)

Modicon M580 with firmware prior to V2.50 Modicon M340 with firmware prior to V3.01 BMxCRA312xx with firmware prior to V2.40 All firmware of Modicon Premium and 140CRA312xxx Modicon M580 with firmware prior to V2.50 Modicon M340 with firmware prior to V3.01 BMxCRA312xx with firmware prior to V2.40 All firmware versions of Modicon Premium and 140CRA312xxx

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.