CVE-2018-7811
9.8
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.5% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-640 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-11-30 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| schneider-electric | modicom bmxnor0200h |
| schneider-electric | modicom bmxnor0200h firmware |
| schneider-electric | modicom m340 |
| schneider-electric | modicom m340 firmware |
| schneider-electric | modicom premium |
| schneider-electric | modicom premium firmware |
| schneider-electric | modicom quantum |
| schneider-electric | modicom quantum firmware |
References
- https://security.cse.iitk.ac.in/responsible-disclosure
- https://www.schneider-electric.com/en/download/document/SEVD-2018-327-01/
- https://www.tenable.com/security/research/tra-2018-38
- https://security.cse.iitk.ac.in/responsible-disclosure
- https://www.schneider-electric.com/en/download/document/SEVD-2018-327-01/
- https://www.tenable.com/security/research/tra-2018-38
→ the Explorer · watch your stack · NVD