ZeroHour

CVE-2018-7833

CVSS 3.0
7.5 high
EPSS
1%p70
Published
()
Modified
Description

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where an unauthenticated user can send a specially crafted XML data via a POST request to cause the web server to become unavailable

Vendors
schneider-electric
Products
modicom m340 firmware, modicom premium firmware, modicom quantum firmware, modicom bmxnor0200h firmware
Weakness
CWE-754
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.