CVE-2018-7812

HIGH

Modicon M340-Quantum - Info Disclosure

Title source: llm
STIX 2.1

Description

An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Scores

CVSS v3 7.5
EPSS 0.0083
EPSS Percentile 74.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (4)
schneider-electric/modicom_bmxnor0200h_firmware
schneider-electric/modicom_m340_firmware
schneider-electric/modicom_premium_firmware
schneider-electric/modicom_quantum_firmware
Published Dec 17, 2018
Tracked Since Feb 18, 2026