Versio.io

CVE-2018-7838

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 15-07-2019 11:15
Last modified: - 19-04-2022 05:36
Total changes: - 5

Description

A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
None
Confidentiality
None
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
7.5
Base score
3.9
3.6
Exploitability score
Impact score
 

Verification logic

OR
AND
OR
vendor=schneider-electric AND product=bmenoc0301_firmware AND versionEndExcluding=2.16
OR
vendor=schneider-electric AND product=bmenoc0301 AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep584040_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep584040s AND version=-
vendor=schneider-electric AND product=bmeh584040 AND version=-
vendor=schneider-electric AND product=bmeh584040c AND version=-
vendor=schneider-electric AND product=modicon_m580_bmep584040 AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep586040_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep586040c AND version=-
vendor=schneider-electric AND product=modicon_m580_bmep586040 AND version=-
AND
OR
vendor=schneider-electric AND product=bmeh586040_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=bmeh586040 AND version=-
vendor=schneider-electric AND product=bmeh586040c AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep581020_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep581020h AND version=-
vendor=schneider-electric AND product=modicon_m580_bmep581020 AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep582020_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep582020h AND version=-
vendor=schneider-electric AND product=modicon_m580_bmep582020 AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep582040_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep582040 AND version=-
vendor=schneider-electric AND product=modicon_m580_bmep582040h AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep583020_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep583020 AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep583040_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep583040 AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep584020_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep584020 AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep585040_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep585040 AND version=-
vendor=schneider-electric AND product=modicon_m580_bmep585040c AND version=-
AND
OR
vendor=schneider-electric AND product=modicon_m580_bmep582040s_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=modicon_m580_bmep582040s AND version=-
AND
OR
vendor=schneider-electric AND product=bmeh582040_firmware AND versionEndExcluding=2.90
OR
vendor=schneider-electric AND product=bmeh582040 AND version=-
vendor=schneider-electric AND product=bmeh582040c AND version=-
 

Reference

 


Keywords

NVD

 

CVE-2018-7838

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.