A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
Bmeh582040 Subscribe
Bmeh582040 Firmware Subscribe
Bmeh582040c Subscribe
Bmeh584040 Subscribe
Bmeh584040c Subscribe
Bmeh586040 Subscribe
Bmeh586040 Firmware Subscribe
Bmeh586040c Subscribe
Bmenoc0301 Subscribe
Bmenoc0301 Firmware Subscribe
Modicon M580 Bmep581020 Subscribe
Modicon M580 Bmep581020 Firmware Subscribe
Modicon M580 Bmep581020h Subscribe
Modicon M580 Bmep582020 Subscribe
Modicon M580 Bmep582020 Firmware Subscribe
Modicon M580 Bmep582020h Subscribe
Modicon M580 Bmep582040 Subscribe
Modicon M580 Bmep582040 Firmware Subscribe
Modicon M580 Bmep582040h Subscribe
Modicon M580 Bmep582040s Subscribe
Modicon M580 Bmep582040s Firmware Subscribe
Modicon M580 Bmep583020 Subscribe
Modicon M580 Bmep583020 Firmware Subscribe
Modicon M580 Bmep583040 Subscribe
Modicon M580 Bmep583040 Firmware Subscribe
Modicon M580 Bmep584020 Subscribe
Modicon M580 Bmep584020 Firmware Subscribe
Modicon M580 Bmep584040 Subscribe
Modicon M580 Bmep584040 Firmware Subscribe
Modicon M580 Bmep584040s Subscribe
Modicon M580 Bmep585040 Subscribe
Modicon M580 Bmep585040 Firmware Subscribe
Modicon M580 Bmep585040c Subscribe
Modicon M580 Bmep586040 Subscribe
Modicon M580 Bmep586040 Firmware Subscribe
Modicon M580 Bmep586040c Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-19550 A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-05T06:37:59.463Z

Reserved: 2018-03-08T00:00:00

Link: CVE-2018-7838

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-15T21:15:10.477

Modified: 2024-11-21T04:12:51.240

Link: CVE-2018-7838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses