5
CVSSv2

CVE-2018-7812

Published: 17/12/2018 Updated: 28/12/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric modicom_m340_firmware

schneider-electric modicom_premium_firmware

schneider-electric modicom_quantum_firmware

schneider-electric modicom_bmxnor0200h_firmware