← All CVEs

CVE-2018-7846

critical · 9.8

A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.

9.8
CVSS
29.6%
EPSS (exploit prob.)
98th
EPSS percentile
2019-05-22
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-668

Affected products

VendorProductAffected versions
schneider-electricmodicon_m580_firmwareall versions
schneider-electricmodicon_m580all versions
schneider-electricmodicon_m340_firmwareall versions
schneider-electricmodicon_m340all versions
schneider-electricmodicon_quantum_firmwareall versions
schneider-electricmodicon_quantumall versions
schneider-electricmodicon_premium_firmwareall versions
schneider-electricmodicon_premiumall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-7846