Vulnerabilities > Schneider Electric > Modicon M340 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2018-7849 Improper Handling of Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause a possible Denial of Service due to improper data integrity check when sending files the controller over Modbus.
network
low complexity
schneider-electric CWE-755
7.5
2019-05-22 CVE-2018-7848 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading files from the controller over Modbus
network
low complexity
schneider-electric CWE-200
7.5
2019-05-22 CVE-2018-7845 Out-of-bounds Read vulnerability in Schneider-Electric products
A CWE-125: Out-of-bounds Read vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.
network
low complexity
schneider-electric CWE-125
7.5
2019-05-22 CVE-2018-7843 Out-of-bounds Read vulnerability in Schneider-Electric products
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
network
low complexity
schneider-electric CWE-125
7.5