Vulnerability Description
A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Micom P141 Firmware | - |
| Schneider-Electric | Micom P141 | - |
| Schneider-Electric | Micom P142 Firmware | - |
| Schneider-Electric | Micom P142 | - |
| Schneider-Electric | Micom P143 Firmware | - |
| Schneider-Electric | Micom P143 | - |
| Schneider-Electric | Micom P145 Firmware | - |
| Schneider-Electric | Micom P145 | - |
| Schneider-Electric | Micom P642 Firmware | - |
| Schneider-Electric | Micom P642 | - |
| Schneider-Electric | Micom P643 Firmware | - |
| Schneider-Electric | Micom P643 | - |
| Schneider-Electric | Micom P645 Firmware | - |
| Schneider-Electric | Micom P645 | - |
| Schneider-Electric | Micom P849 Firmware | - |
| Schneider-Electric | Micom P849 | - |
| Schneider-Electric | Micom P746 Firmware | - |
| Schneider-Electric | Micom P746 | - |
| Schneider-Electric | Micom P841A Firmware | - |
| Schneider-Electric | Micom P841A | - |
Related Weaknesses (CWE)
References
- https://www.schneider-electric.com/en/download/document/SEVD-2018-074-02/Vendor Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2018-074-03/Vendor Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2018-074-04/Vendor Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2018-074-02/Vendor Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2018-074-03/Vendor Advisory
- https://www.schneider-electric.com/en/download/document/SEVD-2018-074-04/Vendor Advisory
FAQ
What is CVE-2018-7758?
CVE-2018-7758 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated c...
How severe is CVE-2018-7758?
CVE-2018-7758 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7758?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Micom P141 Firmware, Schneider-Electric Micom P141, Schneider-Electric Micom P142 Firmware, Schneider-Electric Micom P142, Schneider-Electric Micom P143 Firmware.