Description
A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.
Published: 2019-07-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-19550 A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.
History

No history.

Subscriptions

Schneider-electric Bmeh582040 Bmeh582040 Firmware Bmeh582040c Bmeh584040 Bmeh584040c Bmeh586040 Bmeh586040 Firmware Bmeh586040c Bmenoc0301 Bmenoc0301 Firmware Modicon M580 Bmep581020 Modicon M580 Bmep581020 Firmware Modicon M580 Bmep581020h Modicon M580 Bmep582020 Modicon M580 Bmep582020 Firmware Modicon M580 Bmep582020h Modicon M580 Bmep582040 Modicon M580 Bmep582040 Firmware Modicon M580 Bmep582040h Modicon M580 Bmep582040s Modicon M580 Bmep582040s Firmware Modicon M580 Bmep583020 Modicon M580 Bmep583020 Firmware Modicon M580 Bmep583040 Modicon M580 Bmep583040 Firmware Modicon M580 Bmep584020 Modicon M580 Bmep584020 Firmware Modicon M580 Bmep584040 Modicon M580 Bmep584040 Firmware Modicon M580 Bmep584040s Modicon M580 Bmep585040 Modicon M580 Bmep585040 Firmware Modicon M580 Bmep585040c Modicon M580 Bmep586040 Modicon M580 Bmep586040 Firmware Modicon M580 Bmep586040c
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-05T06:37:59.463Z

Reserved: 2018-03-08T00:00:00.000Z

Link: CVE-2018-7838

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-15T21:15:10.477

Modified: 2024-11-21T04:12:51.240

Link: CVE-2018-7838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses