Lucene search

K
cve[email protected]CVE-2018-8872
HistoryMay 04, 2018 - 5:29 p.m.

CVE-2018-8872

2018-05-0417:29:00
CWE-119
web.nvd.nist.gov
26
schneider electric
triconex
tricon mp
firmware
vulnerability
cve-2018-8872
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.1%

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.

Affected configurations

NVD
Node
schneider-electrictriconex_tricon_mp_3008_firmwareRange10.010.4
AND
schneider-electrictriconex_tricon_mp_3008Match-

CNA Affected

[
  {
    "product": "Triconex Tricon",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "status": "affected",
        "version": "MP model 3008 firmware versions 10.0-10.4"
      }
    ]
  }
]

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.1%

Related for CVE-2018-8872