Modicon Quantum TFTP Arbitrary File Upload

High Nessus Plugin ID 57600


The remote Modicon Quantum controller allows uploading arbitrary files over TFTP.


The remote device is a Modicon Quantum Controller that allows arbitrary file uploads. This can facilitate other attacks since an arbitrary amount of code can be stored on the device and run at a later time.

Additionally, a denial of service vulnerability exists where an attacker can fill the ramdisk and cause the system to crash.


Block access to the TFTP port.

Plugin Details

Severity: High

ID: 57600

File Name: scada_modicon_tftp_enabled.nbin

Version: $Revision: 1.29 $

Type: remote

Family: SCADA

Published: 2012/01/19

Modified: 2018/01/29

Dependencies: 11819, 23821

Risk Information

Risk Factor: High


Base Score: 9

Temporal Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

Temporal Vector: CVSS2#E:F/RL:U/RC:ND

Vulnerability Information

Required KB Items: ftp/modicon/user, ftp/modicon/pass

Exploit Available: true

Exploit Ease: Exploits are available

Reference Information

BID: 51605

OSVDB: 78613

ICS-ALERT: 12-020-03