ZeroHour

CVE-2018-8872

CVSS 3.0
8.1 high
EPSS
2%p82
Published
()
Modified
Description

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.

Vendors
schneider-electric
Products
triconex tricon mp 3008 firmware
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.