A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
140cpu31110 Subscribe
140cpu31110 Firmware Subscribe
140cpu31110c Subscribe
140cpu31110c Firmware Subscribe
140cpu43412u Subscribe
140cpu43412u Firmware Subscribe
140cpu43412uc Subscribe
140cpu43412uc Firmware Subscribe
140cpu65150 Subscribe
140cpu65150 Firmware Subscribe
140cpu65150c Subscribe
140cpu65150c Firmware Subscribe
140cpu65160 Subscribe
140cpu65160 Firmware Subscribe
140cpu65160c Subscribe
140cpu65160c Firmware Subscribe
140cpu65160s Subscribe
140cpu65160s Firmware Subscribe
140cpu65260 Subscribe
140cpu65260 Firmware Subscribe
140cpu65260c Subscribe
140cpu65260c Firmware Subscribe
140cpu65860 Subscribe
140cpu65860 Firmware Subscribe
140cpu65860c Subscribe
140cpu65860c Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-18979 A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-05T06:24:11.250Z

Reserved: 2018-02-19T00:00:00

Link: CVE-2018-7240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-18T20:29:00.247

Modified: 2024-11-21T04:11:51.400

Link: CVE-2018-7240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses