PT-2017-4345 · Schneider Electric · Triconex Tricon Mp 3008

Published

2017-12-13

·

Updated

2019-10-09

·

CVE-2018-8872

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Schneider Electric Triconex Tricon MP 3008 firmware versions 10.0 through 10.4
Description: The issue is related to a buffer overflow in memory, which could allow a remote attacker to gain unauthorized access to protected information. In the affected firmware versions, system calls read directly from memory addresses within the control program area without verification, potentially allowing an attacker to manipulate data and copy it anywhere within memory.
Recommendations: For firmware versions 10.0 through 10.4, consider restricting access to the control program area to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07899
CVE-2018-8872

Affected Products

Triconex Tricon Mp 3008