A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.
2020-04-22T19:15:11.653
2024-11-21T05:37:14.580
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | schneider-electric | ecostruxure_machine_expert | * | Yes |
Application | schneider-electric | somachine | * | Yes |
Application | schneider-electric | somachine_motion | * | Yes |
Operating System | schneider-electric | modicon_m218_firmware | * | Yes |
Hardware | schneider-electric | modicon_m218 | - | No |
Operating System | schneider-electric | modicon_m241_firmware | * | Yes |
Hardware | schneider-electric | modicon_m241 | - | No |
Operating System | schneider-electric | modicon_m251_firmware | * | Yes |
Hardware | schneider-electric | modicon_m251 | - | No |
Operating System | schneider-electric | modicon_m258_firmware | * | Yes |
Hardware | schneider-electric | modicon_m258 | - | No |