peter bassill · operator
$ cve CVE-2018-7811 JSON

CVE-2018-7811

9.8
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.5% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-640
On CISA KEVno
Public exploitnone known
Published2018-11-30
Last modified2026-06-17

Affected (8)

VendorProduct
schneider-electricmodicom bmxnor0200h
schneider-electricmodicom bmxnor0200h firmware
schneider-electricmodicom m340
schneider-electricmodicom m340 firmware
schneider-electricmodicom premium
schneider-electricmodicom premium firmware
schneider-electricmodicom quantum
schneider-electricmodicom quantum firmware

References

→ the Explorer  ·  watch your stack  ·  NVD