CVE-2018-7833

HIGH

Modicon M340, Premium, Quantum, and BMXNOR0200 Firmware - Denial of Service via Crafted XML POST Request

Title source: llm
STIX 2.1

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where an unauthenticated user can send a specially crafted XML data via a POST request to cause the web server to become unavailable

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0046
EPSS Percentile 64.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-754
Status published
Products (4)
schneider-electric/modicom_bmxnor0200h_firmware
schneider-electric/modicom_m340_firmware
schneider-electric/modicom_premium_firmware
schneider-electric/modicom_quantum_firmware
Published Dec 17, 2018
Tracked Since Feb 18, 2026