IM
IronMonkey Threat Research

CVE-2020-7524 HIGH

Published: 2020-08-31 | Last Modified: 2024-11-21 | Status: Modified

Description

Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down. The device does not work properly and must be powered back on to return to normal.

Additional Descriptions (1)

Se presenta una vulnerabilidad de Escritura Fuera de Límites en Modicon M218 Logic Controller (versiones V5.0.0.7 y anteriores) que podría causar una Denegación de Servicio al enviar un paquete IPV4 específico diseñado hacia el controlador: Envío de un paquete de protocolo IPv4 específico hacia Schneider Electric Modicon M218 Logic Controller puede causar que los dispositivos IPv4 se caigan. El dispositivo no funciona apropiadamente y debe volver a encenderse para volver a la normalidad

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Base Score: 5.0 (MEDIUM)

AV:N/AC:L/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-787

Affected Products

Vendor Product Version Update Type
schneider-electric modicon_m218_firmware * <built-in method update of dict object at 0x7e61109d4e00> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:modicon_m218_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:modicon_m218:-:*:*:*:*:*:*:*

References

Notification
Message here