CVE-2018-7824 is an Externally Controlled Reference to a Resource (CWE-610) vulnerability affecting Schneider Electric Modbus Serial Driver versions for 64-bit Windows OS (V3.17 IE 37 and prior), 32-bit Windows OS (V2.17 IE 27 and prior), and Driver Suite (V14.12 and prior). This vulnerability allows a highly privileged attacker to gain write access to system files or other critical user files. With a CVSS score of 4.9 (Medium), it has a network attack vector and low attack complexity, but requires high privileges for exploitation, impacting integrity without affecting confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.17CPE matchmatch criteria | cpe:2.3:a:schneider-electric:modbus_serial_driver:*:*:*:*:*:*:*:* | ||
<= 2.17CPE matchmatch criteria | cpe:2.3:a:schneider-electric:modbus_serial_driver:*:*:*:*:*:*:*:* | ||
<= 14.12CPE matchmatch criteria | cpe:2.3:a:schneider-electric:driver_suite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.