CVE-2018-7848
Severity
7.5HIGH
EPSS
11.5%
top 6.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateMay 24
Description
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading files from the controller over Modbus
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
▶CVEListV5modicon_m580_modicon_m340_modicon_quantum_modicon_premiumModicon M580 Modicon M340 Modicon Quantum Modicon Premium
🔴Vulnerability Details
2GHSA▶
GHSA-7jwj-69w8-5fmm: A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which cou↗2022-05-24
CVEList▶
CVE-2018-7848: A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which cou↗2019-05-22