CVE-2018-7811
Summary
| CVE | CVE-2018-7811 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-30 19:29:00 UTC |
| Updated | 2019-10-02 13:15:00 UTC |
| Description | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server |
Risk And Classification
Problem Types: CWE-640
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Responsible Disclosure | Indian Institute of Technology, Kanpur | MISC | security.cse.iitk.ac.in | |
| [R1] Multiple Schneider Electric Modicon Quantum Vulnerabilities - Research Advisory | Tenable® | MISC | www.tenable.com | Exploit, Third Party Advisory |
| Security Notification - Embedded Web Servers for Modicon (V3.2) | Schneider Electric | CONFIRM | www.schneider-electric.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590900 Schneider Electric Embedded Web Servers for Modicon Multiple Vulnerabilities (SEVD-2018-327-01)