6.8
CVE-2018-7824
- EPSS 0.19%
- Veröffentlicht 22.05.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:47
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Modbus Serial Driver Version <= 3.17
Schneider-electric ≫ Modbus Serial Driver Version <= 2.17
Schneider-electric ≫ Driver Suite Version <= 14.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.19% | 0.412 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 6.8 | 8 | 6.9 |
AV:N/AC:L/Au:S/C:N/I:C/A:N
|
CWE-610 Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.