Check Point Reference: | CPAI-2019-0854 |
Date Published: | 24 Jul 2019 |
Severity: | Critical |
Last Updated: | Wednesday 24 July, 2019 |
Source: | |
Industry Reference: | CVE-2018-7809 CVE-2018-7810 CVE-2018-7811 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Schneider Electric Modicon M340 Quantum PLC Schneider Electric Modicon M340 Premium Schneider Electric Modicon M340 BMXNOR0200 |
Vulnerability Description | Multiple authentication bypass vulnerabilities exist in Schneider Electric Modicon. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to the affected page. Successful exploitation results in the attacker being able to change the password for arbitrary accounts. |
This protection detects attempts to exploit this vulnerability.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: SCADA Protection Violation.
Attack Information: Schneider Electric Modicon Multiple Authentication Bypass Vulnerabilities