CVE-2018-7809

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_m340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_m340:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_premium_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_premium:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_quantum_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_quantum:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_bmxnor0200h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_bmxnor0200h:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:12

Type Values Removed Values Added
References () https://www.schneider-electric.com/en/download/document/SEVD-2018-327-01/ - Vendor Advisory () https://www.schneider-electric.com/en/download/document/SEVD-2018-327-01/ - Vendor Advisory
References () https://www.tenable.com/security/research/tra-2018-38 - Exploit, Third Party Advisory () https://www.tenable.com/security/research/tra-2018-38 - Exploit, Third Party Advisory

Information

Published : 2018-11-30 19:29

Updated : 2024-11-21 04:12


NVD link : CVE-2018-7809

Mitre link : CVE-2018-7809

CVE.ORG link : CVE-2018-7809


JSON object : View

Products Affected

schneider-electric

  • modicom_m340
  • modicom_quantum_firmware
  • modicom_quantum
  • modicom_bmxnor0200h_firmware
  • modicom_premium
  • modicom_m340_firmware
  • modicom_premium_firmware
  • modicom_bmxnor0200h
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password