
CVE-2018-7823
https://notcve.org/view.php?id=CVE-2018-7823
22 May 2019 — A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending crafted ethernet message. Existe una vulnerabilidad de entorno (CWE-2) en SoMachine Basic, todas las versiones y Modicon M221 (todas las referencias, todas las versiones anteriores al firmware V1.10.0.0), que podría generar el inicio remoto de SoMachine Basic cuando se envía un mensaje Ethernet ... • https://www.schneider-electric.com/en/download/document/SEVD-2019-045-01 •

CVE-2018-7822
https://notcve.org/view.php?id=CVE-2018-7822
22 May 2019 — An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting SoMachine Basic. Existe una vulnerabilidad de permisos predeterminados incorrectos (CWE-276) en SoMachine Basic, todas las versiones, y Modicon M221 (todas las referencias, todas las versiones anteriores al firmware V1.10.0.0), que p... • https://www.schneider-electric.com/en/download/document/SEVD-2019-045-01 • CWE-276: Incorrect Default Permissions •

CVE-2018-7821
https://notcve.org/view.php?id=CVE-2018-7821
22 May 2019 — An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated. Existe una vulnerabilidad de entorno (CWE-2) en SoMachine Basic, todas las versiones, y Modicon M221 (todas las referencias, todas las versiones anteriores al firmware V1.10.0.0), que podría generar un impacto en el tiempo del ciclo al i... • https://www.schneider-electric.com/en/download/document/SEVD-2019-045-01 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2019-10953
https://notcve.org/view.php?id=CVE-2019-10953
17 Apr 2019 — ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets. En Controladores lógicos programables de ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - , versiones múltiples. Los investigadores han encontrado que algunos controladores son susceptibles a un ataque de Denegación de Servicio (DoS) debido a una inundación de paquetes de ... • http://www.securityfocus.com/bid/108413 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2018-7790
https://notcve.org/view.php?id=CVE-2018-7790
29 Aug 2018 — An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Modicon M221, the attacker can upload the original program from the PLC. Existe una vulnerabilidad de error de gestión de información en el producto Modicon M221, de Schneider Electric (todas las referencias y toda... • http://www.securityfocus.com/bid/105182 • CWE-294: Authentication Bypass by Capture-replay •

CVE-2018-7791
https://notcve.org/view.php?id=CVE-2018-7791
29 Aug 2018 — A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this vulnerability and overwrite the password, the attacker can upload the original program from the PLC. Existe una vulnerabilidad de permisos, privilegios y control de acceso en el producto Modicon M221, de Schneide... • http://www.securityfocus.com/bid/105182 • CWE-287: Improper Authentication •

CVE-2018-7792
https://notcve.org/view.php?id=CVE-2018-7792
29 Aug 2018 — A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table. Existe una vulnerabilidad de permisos, privilegios y control de acceso en el producto Modicon M221, de Schneider Electric (todas las referencias y todas las versiones anteriores al firmware V1.6.2.0). La vulnerabilidad permite que usuarios no autorizado... • http://www.securityfocus.com/bid/105182 • CWE-862: Missing Authorization •

CVE-2018-7789
https://notcve.org/view.php?id=CVE-2018-7789
29 Aug 2018 — An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames. Existe una vulnerabilidad de comprobación incorrecta de condiciones inusuales o excepcionales en el producto Modicon M221, de Schneider Electric (todas las referencias y todas las versiones anteriores al firmware ... • http://www.securityfocus.com/bid/105171 • CWE-754: Improper Check for Unusual or Exceptional Conditions •

CVE-2017-6030
https://notcve.org/view.php?id=CVE-2017-6030
30 Jun 2017 — A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The affected products generate insufficiently random TCP initial sequence numbers that may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections. Un problema... • http://www.securityfocus.com/bid/97254 • CWE-331: Insufficient Entropy CWE-343: Predictable Value Range from Previous Values •