CVE-2018-7830
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request.
Existe una vulnerabilidad de neutralización incorrecta de secuencias CRLF en cabeceras HTTP ("separación de respuesta HTTP") en los servidores web embebidos en todos los productos Modicon M340, Premium, Quantum PLCs y BMXNOR0200, donde puede ocurrir una denegación de servicio (DoS) durante 1 minuto aproximadamente mediante el envío de una petición HTTP especialmente manipulada.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-03-08 CVE Reserved
- 2018-11-30 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.tenable.com/security/research/tra-2018-38 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.schneider-electric.com/en/download/document/SEVD-2018-327-01 | 2018-12-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Modicom M340 Firmware Search vendor "Schneider-electric" for product "Modicom M340 Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom M340 Search vendor "Schneider-electric" for product "Modicom M340" | - | - |
Safe
|
Schneider-electric Search vendor "Schneider-electric" | Modicom Premium Firmware Search vendor "Schneider-electric" for product "Modicom Premium Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom Premium Search vendor "Schneider-electric" for product "Modicom Premium" | * | - |
Safe
|
Schneider-electric Search vendor "Schneider-electric" | Modicom Quantum Firmware Search vendor "Schneider-electric" for product "Modicom Quantum Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom Quantum Search vendor "Schneider-electric" for product "Modicom Quantum" | * | - |
Safe
|
Schneider-electric Search vendor "Schneider-electric" | Modicom Bmxnor0200h Firmware Search vendor "Schneider-electric" for product "Modicom Bmxnor0200h Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom Bmxnor0200h Search vendor "Schneider-electric" for product "Modicom Bmxnor0200h" | - | - |
Safe
|