In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.
2018-05-04T17:29:00.723
2024-11-21T04:14:29.880
Modified
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | triconex_tricon_mp_3008_firmware | ≤ 10.4 | Yes |
Hardware | schneider-electric | triconex_tricon_mp_3008 | - | No |