5
CVSSv2

CVE-2018-7856

Published: 22/05/2019 Updated: 03/02/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible denial of Service when writing invalid memory blocks to the controller over Modbus.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric modicon_premium_firmware -

schneider-electric modicon_quantum_firmware -

schneider-electric modicon_m340_firmware

schneider-electric modicon_m580_firmware

Github Repositories

A quick and easy way to turn traffic generated by exploit script in to network capture (i.e. PCAP) files.

QuickPcap A quick and easy way to turn traffic generated by exploit script in to network capture (ie PCAP) files Requirement Docker nc Installation / Uninstallation Please run install script before executing standalone quickpcapsh script To remove use uninstall script Usage message for quickpcapsh script Usage: /quickpcapsh [-h] <protocol> <port&