6.4
CVSSv2

CVE-2018-7809

Published: 30/11/2018 Updated: 28/12/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric modicom_m340_firmware

schneider-electric modicom_premium_firmware

schneider-electric modicom_quantum_firmware

schneider-electric modicom_bmxnor0200h_firmware