Denial of Service Vulnerability in Modicon Controllers by Schneider Electric
CVE-2018-7855
7.5HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 22 May 2019
What is CVE-2018-7855?
An uncaught exception vulnerability exists in all versions of Schneider Electric's Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium controllers. This vulnerability could allow an attacker to induce a Denial of Service condition by sending malformed breakpoint parameters to the device over the Modbus protocol. The lack of proper error handling may lead to interruptions in service, affecting the operational reliability of the affected controllers.
Affected Version(s)
Modicon M580 Modicon M340 Modicon Quantum Modicon Premium Modicon M580 Modicon M340 Modicon Quantum Modicon Premium