Description
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
Published: 2018-04-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-18979 A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
History

No history.

Subscriptions

Schneider-electric 140cpu31110 140cpu31110 Firmware 140cpu31110c 140cpu31110c Firmware 140cpu43412u 140cpu43412u Firmware 140cpu43412uc 140cpu43412uc Firmware 140cpu65150 140cpu65150 Firmware 140cpu65150c 140cpu65150c Firmware 140cpu65160 140cpu65160 Firmware 140cpu65160c 140cpu65160c Firmware 140cpu65160s 140cpu65160s Firmware 140cpu65260 140cpu65260 Firmware 140cpu65260c 140cpu65260c Firmware 140cpu65860 140cpu65860 Firmware 140cpu65860c 140cpu65860c Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-05T06:24:11.250Z

Reserved: 2018-02-19T00:00:00.000Z

Link: CVE-2018-7240

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-18T20:29:00.247

Modified: 2024-11-21T04:11:51.400

Link: CVE-2018-7240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses