Vulnerabilities > CVE-2018-7850 - Unspecified vulnerability in Schneider-Electric products

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
schneider-electric

Summary

A CWE-807: Reliance on Untrusted Inputs in a Security Decision vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause invalid information displayed in Unity Pro software.

Talos

idTALOS-2018-0743
last seen2019-06-11
published2019-06-10
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0743
titleSchneider Electric Modicon M580 UnityPro reliance on untrusted inputs vulnerability