CVE-2018-7240 Vulnerability Details

  /     /     /  

CVE-2018-7240 Metadata Quick Info

CVE Published: 18/04/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: schneider | Vendor: Schneider Electric SE | Product: Modicon Quantum
Status : PUBLISHED

CVE-2018-7240 Description

A vulnerability exists in Schneider Electric\'s Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Arbritrary Code Execution
Source: Schneider Electric SE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).