Buffer overflow in Schneider Electric products - CVE-2018-7851
Published: October 3, 2019
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service (DoS) condition on the target system.
The vulnerability exists due to a boundary error when sending a specially crafted Modbus packet. A remote authenticated attacker can trigger memory corruption and cause a denial of service condition to the device that would force a restart to restore availability.
Affected software
140CRA312xxx
Modicon Premium
Modicon M340
Modicon M580
How to mitigate CVE-2018-7851
Modicon M340 - update to 3.01
Modicon M580 - update to 2.50