CVE-2018-7811

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_m340_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_m340:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_premium_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_premium:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_quantum_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_quantum:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:modicom_bmxnor0200h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicom_bmxnor0200h:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-11-30 19:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-7811

Mitre link : CVE-2018-7811

CVE.ORG link : CVE-2018-7811


JSON object : View

Products Affected

schneider-electric

  • modicom_premium_firmware
  • modicom_bmxnor0200h
  • modicom_m340
  • modicom_m340_firmware
  • modicom_quantum
  • modicom_bmxnor0200h_firmware
  • modicom_quantum_firmware
  • modicom_premium
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password