Denial of Service Vulnerability in Modicon M580, M340, Quantum, and Premium Controllers by Schneider Electric
CVE-2018-7857
7.5HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 22 May 2019
Summary
A vulnerability exists in the Modicon M580, M340, Quantum, and Premium controllers by Schneider Electric. This issue allows for Denial of Service conditions due to an uncaught exception when writing out of bounds variables to the controller via Modbus. If exploited, this can lead to unexpected behaviors, including potential interruption of service. Users are encouraged to apply available updates and follow best practices for securing their networks.
Affected Version(s)
Modicon M580 Modicon M340 Modicon Quantum Modicon Premium Modicon M580 Modicon M340 Modicon Quantum Modicon Premium
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved