RULE(RULE ID:338512)

Rule General Information
Release Date: 2024-11-05
Rule Name: Schneider Electric Modicon Password Reset Vulnerability (CVE-2018-7811)
Severity:
CVE ID:
Rule Protection Details
Description: Schneider Electric Modicon is a programmable logic controller widely used in industrial automation and control systems. Schneider Electric Modicon has a password reset vulnerability. The vulnerability allows an unauthenticated remote user to access a Web server's password-changing capability.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://security.cse.iitk.ac.in/responsible-disclosure
https://www.schneider-electric.com/en/download/document/SEVD-2018-327-01/
https://www.tenable.com/security/research/tra-2018-38
Solutions
Refer to the announcement or patch by the vendor: https://www.schneider-electric.com/