A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
140cpu31110
Subscribe
140cpu31110 Firmware
Subscribe
140cpu31110c
Subscribe
140cpu31110c Firmware
Subscribe
140cpu43412u
Subscribe
140cpu43412u Firmware
Subscribe
140cpu43412uc
Subscribe
140cpu43412uc Firmware
Subscribe
140cpu65150
Subscribe
140cpu65150 Firmware
Subscribe
140cpu65150c
Subscribe
140cpu65150c Firmware
Subscribe
140cpu65160
Subscribe
140cpu65160 Firmware
Subscribe
140cpu65160c
Subscribe
140cpu65160c Firmware
Subscribe
140cpu65160s
Subscribe
140cpu65160s Firmware
Subscribe
140cpu65260
Subscribe
140cpu65260 Firmware
Subscribe
140cpu65260c
Subscribe
140cpu65260c Firmware
Subscribe
140cpu65860
Subscribe
140cpu65860 Firmware
Subscribe
140cpu65860c
Subscribe
140cpu65860c Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18979 | A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-05T06:24:11.250Z
Reserved: 2018-02-19T00:00:00
Link: CVE-2018-7240
No data.
Status : Modified
Published: 2018-04-18T20:29:00.247
Modified: 2024-11-21T04:11:51.400
Link: CVE-2018-7240
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD