PT-2017-3703 · Schneider Electric · Modicon Premium+3
Aleksandr Melkikh
+2
·
Published
2017-04-28
·
Updated
2024-04-10
·
CVE-2018-7761
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Schneider Electric Modicon BMXNOR0200 (affected versions not specified)
Schneider Electric Modicon M340 (affected versions not specified)
Schneider Electric Modicon Premium (affected versions not specified)
Schneider Electric Modicon Quantum PLC (affected versions not specified)
Description:
The issue is related to an error in parsing HTTP requests in the embedded web server of the affected devices. This could allow a remote attacker to execute arbitrary code on the web server using specially crafted HTTP requests.
Recommendations:
For Schneider Electric Modicon BMXNOR0200, consider disabling the HTTP request parser until a patch is available.
For Schneider Electric Modicon M340, restrict access to the web server to minimize the risk of exploitation.
For Schneider Electric Modicon Premium, avoid using the web server for critical operations until the issue is resolved.
For Schneider Electric Modicon Quantum PLC, limit network exposure of the device to reduce the risk of remote exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modicon Bmxnor0200
Modicon M340
Modicon Premium
Modicon Quantum Plc