Vulnerabilities > CVE-2018-7854 - Improper Check for Unusual or Exceptional Conditions vulnerability in Schneider-Electric products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
schneider-electric
CWE-754

Summary

A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a denial of Service when sending invalid debug parameters to the controller over Modbus.

Talos

idTALOS-2019-0765
last seen2019-06-10
published2019-06-10
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0765
titleSchneider Electric Modicon M580 UMAS function code 0x65 denial-of-service vulnerability