Reliance on untrusted inputs in a security decision in Schneider Electric products - CVE-2018-7850
Published: October 3, 2019
Vulnerability identifier: #VU21510
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7850
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause modification of sensitive data.
The vulnerability exists due to the application uses a protection mechanism that relies on the existence or values of an input, but the input can be modified in a way that bypasses the protection mechanism. A remote attacker can cause invalid information displayed in Unity Pro software.
Affected software
Modicon Quantum
Modicon Premium
Modicon M340
Modicon M580
Modicon Premium
Modicon M340
Modicon M580
How to mitigate CVE-2018-7850
Install updates from vendor's website.
Modicon M340 - update to 3.10
Modicon M580 - update to 2.90
Modicon M580 - update to 2.90