High severity7.5NVD Advisory· Published Dec 17, 2018· Updated Jun 17, 2026
CVE-2018-7833
CVE-2018-7833
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where an unauthenticated user can send a specially crafted XML data via a POST request to cause the web server to become unavailable
Affected products
6- cpe:2.3:o:schneider-electric:modicom_bmxnor0200h_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicom_m340_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicom_premium_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicom_quantum_firmware:*:*:*:*:*:*:*:*
- Schneider Electric SE/Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200v5Range: Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200
Patches
Vulnerability mechanics
References
1- www.schneider-electric.com/en/download/document/SEVD-2018-327-01/nvdVendor Advisory
News mentions
0No linked articles in our index yet.