Multiple Schneider Electric Modicon Products CVE-2018-7241 Remote Security Vulnerability
BID:103542
CVE-2018-7241 |Info
Multiple Schneider Electric Modicon Products CVE-2018-7241 Remote Security Vulnerability
| Bugtraq ID: | 103542 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-7241 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2018 12:00AM |
| Updated: | Mar 22 2018 12:00AM |
| Credit: | Nikita Maximov (Positive Technologies) |
| Vulnerable: |
Schneider-Electric Modicon Quantum 0 Schneider-Electric Modicon Premium 0 Schneider-Electric Modicon M340 0 Schneider-Electric Modicon BMXNOR0200 0 |
| Not Vulnerable: | |
Discussion
Multiple Schneider Electric Modicon Products CVE-2018-7241 Remote Security Vulnerability
Multiple Schneider Electric Modicon products are prone to a remote security vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Multiple Schneider Electric Modicon products are prone to a remote security vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Exploit / POC
Multiple Schneider Electric Modicon Products CVE-2018-7241 Remote Security Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Schneider Electric Modicon Products CVE-2018-7241 Remote Security Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Schneider Electric Modicon Products CVE-2018-7241 Remote Security Vulnerability
References:
References:
- Schneider Electric Homepage (Schneider Electric)
- Advisory (ICSA-18-086-01) Schneider Electric Modicon Premium, Modicon Quantum, M (CERT)
- Security Notification - Embedded FTP Servers for Modicon (Schneider Electric)