CVE-2018-7833
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where an unauthenticated user can send a specially crafted XML data via a POST request to cause the web server to become unavailable
Existe una vulnerabilidad de comprobaciĆ³n incorrecta de condiciones inusuales o excepcionales en los servidores web embebidos en todos los Modicon M340, Premium, Quantum PLCs y BMXNOR0200, donde un usuario no autenticado puede enviar datos XML especialmente manipulados mediante una peticiĆ³n POST para provocar que el servidor web deje de estar disponible.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-03-08 CVE Reserved
- 2018-12-17 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-754: Improper Check for Unusual or Exceptional Conditions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.schneider-electric.com/en/download/document/SEVD-2018-327-01 | 2018-12-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Modicom M340 Firmware Search vendor "Schneider-electric" for product "Modicom M340 Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom M340 Search vendor "Schneider-electric" for product "Modicom M340" | - | - |
Safe
|
Schneider-electric Search vendor "Schneider-electric" | Modicom Premium Firmware Search vendor "Schneider-electric" for product "Modicom Premium Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom Premium Search vendor "Schneider-electric" for product "Modicom Premium" | * | - |
Safe
|
Schneider-electric Search vendor "Schneider-electric" | Modicom Quantum Firmware Search vendor "Schneider-electric" for product "Modicom Quantum Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom Quantum Search vendor "Schneider-electric" for product "Modicom Quantum" | * | - |
Safe
|
Schneider-electric Search vendor "Schneider-electric" | Modicom Bmxnor0200h Firmware Search vendor "Schneider-electric" for product "Modicom Bmxnor0200h Firmware" | * | - |
Affected
| in | Schneider-electric Search vendor "Schneider-electric" | Modicom Bmxnor0200h Search vendor "Schneider-electric" for product "Modicom Bmxnor0200h" | - | - |
Safe
|