PT-2018-1526 · Schneider Electric · Modicon M221

Yehonatan Kfir

·

Published

2018-07-30

·

Updated

2026-05-29

·

CVE-2018-7789

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Modicon M221 versions prior to V1.6.2.0
Description The issue is related to an improper check for unusual or exceptional conditions, allowing unauthorized users to remotely reboot the device using crafted programming protocol frames. This can be exploited by a remote attacker to reboot the Modicon M221 device.
Recommendations For versions prior to V1.6.2.0, update the firmware to version V1.6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting remote access to the device until the update can be applied.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01081
CVE-2018-7789

Affected Products

Modicon M221