CVE-2020-7524

Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down. The device does not work properly and must be powered back on to return to normal.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m218_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m218:-:*:*:*:*:*:*:*

History

31 Jan 2022, 19:52

Type Values Removed Values Added
CPE cpe:2.3:o:se:modicon_m218_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:se:modicon_m218:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m218:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:modicon_m218_firmware:*:*:*:*:*:*:*:*

26 Aug 2021, 14:43

Type Values Removed Values Added
CPE cpe:2.3:h:schneider-electric:modicon_m218:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m218:-:*:*:*:*:*:*:*

19 Aug 2021, 18:21

Type Values Removed Values Added
CPE cpe:2.3:o:schneider-electric:modicon_m218_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m218_firmware:*:*:*:*:*:*:*:*

Information

Published : 2020-08-31 17:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-7524

Mitre link : CVE-2020-7524

CVE.ORG link : CVE-2020-7524


JSON object : View

Products Affected

schneider-electric

  • modicon_m218
  • modicon_m218_firmware
CWE
CWE-787

Out-of-bounds Write