In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.
2018-05-04T17:29:00.393
2024-11-21T04:12:17.490
Modified
CVSSv3.0: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | schneider-electric | triconex_tricon_mp_3008_firmware | ≤ 10.0-10.4 | Yes |
| Hardware | schneider-electric | triconex_tricon_mp_3008 | - | No |