Schneider Electric Modicon M221 Improper Check For Unusual or Exceptional Conditions (CVE-2018-7789)

high Tenable OT Security Plugin ID 500870

Synopsis

The remote OT asset is affected by a vulnerability.

Description

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Schneider Electric reports that a fix for this vulnerability is implemented in Modicon M221 Firmware v1.6.2.0, delivered within SoMachine Basic v1.6 SP2, or by using the Schneider Electric Software Update tool.

The download for SoMachine Basic is available at:

https://www.schneider-electric.com/en/download/document/SoMachineBasicV1.6SP2/

For more information, see the Schneider Electric security notification at:

https://www.schneider-electric.com/en/download/document/SEVD-2018-233-01/

See Also

http://www.securityfocus.com/bid/105171

https://ics-cert.us-cert.gov/advisories/ICSA-18-240-02

http://www.nessus.org/u?12e48d72

Plugin Details

Severity: High

ID: 500870

Version: 1.8

Type: remote

Family: Tenable.ot

Published: 3/1/2023

Updated: 3/4/2024

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2018-7789

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:schneider-electric:modicon_m221_series_firmware

Required KB Items: Tenable.ot/Schneider

Exploit Ease: No known exploits are available

Patch Publication Date: 8/29/2018

Vulnerability Publication Date: 8/29/2018

Reference Information

CVE: CVE-2018-7789

CWE: 754