Vulnerabilities > Schneider Electric > Modicon Quantum Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2018-7846 Exposure of Resource to Wrong Sphere vulnerability in Schneider-Electric products
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
network
low complexity
schneider-electric CWE-668
5.0
2019-05-22 CVE-2018-7845 Out-of-bounds Read vulnerability in Schneider-Electric products
A CWE-125: Out-of-bounds Read vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.
network
low complexity
schneider-electric CWE-125
5.0
2019-05-22 CVE-2018-7843 Out-of-bounds Read vulnerability in Schneider-Electric products
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
network
low complexity
schneider-electric CWE-125
5.0
2019-05-22 CVE-2018-7842 Authentication Bypass by Spoofing vulnerability in Schneider-Electric products
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
network
low complexity
schneider-electric CWE-290
7.5
2019-05-22 CVE-2018-7788 Credentials Management vulnerability in Schneider-Electric Modicon Quantum Firmware
A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40.
network
low complexity
schneider-electric CWE-255
4.0