PT-2019-2275 · Schneider Electric · Modicon M340+3

Publicado

2019-05-14

·

Atualizado

2022-02-03

·

CVE-2018-7847

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Modicon M580 versions (affected versions not specified) Modicon M340 versions (affected versions not specified) Modicon Quantum versions (affected versions not specified) Modicon Premium versions (affected versions not specified)
Description The issue is related to errors in access control. It may allow a remote attacker to cause a denial of service or execute arbitrary code by overwriting the controller's configuration settings using the Modbus protocol.
Recommendations For Modicon M580, update the configuration to restrict access to the Modbus protocol until a patch is available. For Modicon M340, consider disabling remote access to the controller until a fix is provided. For Modicon Quantum, restrict modifications to the controller's configuration settings to minimize the risk of exploitation. For Modicon Premium, avoid using the Modbus protocol for configuration changes until the issue is resolved. As a temporary workaround, consider restricting access to the Modbus protocol for all affected controllers until a patch is available.

Exploit

Correção

Improper Authentication

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02046
CVE-2018-7847

Produtos afetados

Modicon M340
Modicon M580
Modicon Premium
Modicon Quantum