CVE-2018-7759 PUBLISHED CVSS 7.5 HIGH

A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. The buffer overflow vulnerability is caused by the length of the source string specified (instead of the buffer size) as the number of bytes to be copied.

EPSS 0.82% · 74.3th percentile

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.82%
74.3th percentile

Affected Products

VendorProductVersions
schneider-electrictsxp574634m_firmware
schneider-electrictsxh5744m_firmware
schneider-electricmodicon_m340_bmxp3420102cl_firmware
schneider-electrictsxp576634m_firmware
schneider-electrictsxp57454m_firmware
schneider-electric140cpu65260c_firmware
schneider-electrictsxp57104m_firmware
schneider-electrictsxp57354m_firmware
schneider-electrictsxh5744mc_firmware
schneider-electrictsxp57104mc_firmware
schneider-electric140cpu65860_firmware
schneider-electrictsxp573634m_firmware
schneider-electrictsxp57554m_firmware
schneider-electrictsxp57154m_firmware
schneider-electrictsxp57354mc_firmware
schneider-electrictsxp57554mc_firmware
schneider-electric140cpu43412uc_firmware
schneider-electricmodicon_m340_bmxp342020h_firmware
schneider-electrictsxp573634mc_firmware
schneider-electrictsxp575634mc_firmware

…and 38 more

Timeline

References

Open in Interactive Console →