CVE-2018-7792

HIGH

Schneider Electric Modicon M221 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105182
Mitigation, Vendor Advisory x_refsource_confirm
https://www.schneider-electric.com/en/download/document/SEVD-2018-235-01/

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-862
Status published
Products (1)
schneider-electric/modicon_m221_firmware < 1.6.2.0
Published Aug 29, 2018
Tracked Since Feb 18, 2026