CVE-2018-7791

CRITICAL

Schneider Electric's Modicon M221 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this vulnerability and overwrite the password, the attacker can upload the original program from the PLC.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105182
Mitigation, Vendor Advisory x_refsource_confirm
https://www.schneider-electric.com/en/download/document/SEVD-2018-235-01/

Scores

CVSS v3 9.8
EPSS 0.0035
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
schneider-electric/modicon_m221_firmware < 1.6.2.0
Published Aug 29, 2018
Tracked Since Feb 18, 2026