Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-7846 PoC — 多款Schneider Electric产品缓冲区错误漏洞

Source
Associated Vulnerability
Title:多款Schneider Electric产品缓冲区错误漏洞 (CVE-2018-7846)
Description:A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
Description
CVE-2018-7846
Readme
# CVE-2018-7846

### Affected Products

* **Schneider Electric Modicon M580** Version < 2.90

* **Schneider Electric Modicon M340** Version < 3.10

* **Schneider Electric Modicon Premium** All Versions

* **Schneider Electric Modicon Quantum** All Versions

### References

* [https://www.se.com/ww/en/download/document/SEVD-2019-134-11/](https://www.se.com/ww/en/download/document/SEVD-2019-134-11/)

* [https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0735](https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0735)

# Usage

```
python CVE-2018-7846.py --host 192.168.1.123
```
File Snapshot

[4.0K] /data/pocs/3196c429cfc13839a03b5643197f1838f769c7db ├── [1.2K] CVE-2018-7846.py └── [ 613] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →