CVE-2018-7792 is a high-severity permissions, privileges, and access control vulnerability affecting all versions of Schneider Electric Modicon M221 firmware prior to V1.6.2.0. This flaw allows unauthorized attackers to decode device passwords using rainbow tables, potentially granting full access to the controller. With a CVSS score of 7.5, it represents a significant risk due to its low attack complexity and network-based vector, leading to high confidentiality impact. While no public exploits, Metasploit modules, or significant community discussion have been identified, the vulnerability remains a critical concern for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.2.0CPE matchmatch criteria | cpe:2.3:o:schneider-electric:modicon_m221_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.