Back to search
CVE-2018-7240
Published: Apr 18, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.
| Vendor | Product | Versions |
|---|---|---|
Schneider Electric SE | Modicon Quantum | affected All versions of Modicon Quantum communication modules |
References
https://www.schneider-electric.com/en/download/document/SEVD-2018-081-01/
x_refsource_CONFIRM
103541
vdb-entry
x_refsource_BID
https://ics-cert.us-cert.gov/advisories/ICSA-18-086-01
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now