CVE-2018-7809

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_m340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_m340:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_premium_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_premium:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_quantum_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_quantum:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_bmxnor0200h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_bmxnor0200h:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-11-30 19:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-7809

Mitre link : CVE-2018-7809

CVE.ORG link : CVE-2018-7809


JSON object : View

Products Affected

schneider-electric

  • modicom_m340_firmware
  • modicom_premium
  • modicom_bmxnor0200h
  • modicom_quantum_firmware
  • modicom_premium_firmware
  • modicom_bmxnor0200h_firmware
  • modicom_quantum
  • modicom_m340
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password