Schneider Electric Modicon M221 Multiple Security Bypass Vulnerabilities
BID:105182
Info
Schneider Electric Modicon M221 Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 105182 |
| Class: | Design Error |
| CVE: |
CVE-2018-7790 CVE-2018-7791 CVE-2018-7792 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2018 12:00AM |
| Updated: | Aug 28 2018 12:00AM |
| Credit: | Irfan Ahmed, Hyunguk Yoo, Sushma Kalle, and Nehal Ameen of the University of New Orleans. |
| Vulnerable: |
Schneider-Electric Modicon M221 1.5.0.1 Schneider-Electric Modicon M221 1.5.0.0 Schneider-Electric Modicon M221 0 |
| Not Vulnerable: |
Schneider-Electric Modicon M221 1.6.2.0 |
Discussion
Schneider Electric Modicon M221 Multiple Security Bypass Vulnerabilities
Schneider Electric Modicon M221 is prone to multiple security-bypass vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Schneider Electric Modicon M221 1.6.2.0 are vulnerable.
Schneider Electric Modicon M221 is prone to multiple security-bypass vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Schneider Electric Modicon M221 1.6.2.0 are vulnerable.
Exploit / POC
Schneider Electric Modicon M221 Multiple Security Bypass Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Schneider Electric Modicon M221 Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Schneider Electric Modicon M221 Multiple Security Bypass Vulnerabilities
References:
References:
- Schneider Electric HomePage (Schneider Electric)
- Advisory (ICSA-18-240-01) Schneider Electric Modicon M221 (CERT)