CVE-2018-7758
Last modified
CVE-2018-7758 is a vulnerability of currently unknown severity. A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Micom P141 Firmware | All versions |
| Schneider-Electric | Micom P142 Firmware | All versions |
| Schneider-Electric | Micom P143 Firmware | All versions |
| Schneider-Electric | Micom P145 Firmware | All versions |
| Schneider-Electric | Micom P642 Firmware | All versions |
| Schneider-Electric | Micom P643 Firmware | All versions |
| Schneider-Electric | Micom P645 Firmware | All versions |
| Schneider-Electric | Micom P849 Firmware | All versions |
| Schneider-Electric | Micom P746 Firmware | All versions |
| Schneider-Electric | Micom P841a Firmware | All versions |
| Schneider-Electric | Micom P841b Firmware | All versions |
| Schneider-Electric | Micom P443 Firmware | All versions |
| Schneider-Electric | Micom P445 Firmware | All versions |
| Schneider-Electric | Micom P446 Firmware | All versions |
| Schneider-Electric | Micom P441 Firmware | All versions |
| Schneider-Electric | Micom P442 Firmware | All versions |
| Schneider-Electric | Micom P444 Firmware | All versions |
| Schneider-Electric | Micom P541 Firmware | All versions |
| Schneider-Electric | Micom P542 Firmware | All versions |
| Schneider-Electric | Micom P543 Firmware | All versions |
| Schneider-Electric | Micom P544 Firmware | All versions |
| Schneider-Electric | Micom P545 Firmware | All versions |
| Schneider-Electric | Micom P546 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7758?
How severe is CVE-2018-7758?
How do I fix CVE-2018-7758?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7752GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc…
- CVE-2018-7753An issue was discovered in Bleach 2.1.x before 2.1.3. Attrib…
- CVE-2018-7754The aoedisk_debugfs_show function in drivers/block/aoe/aoebl…
- CVE-2018-7755An issue was discovered in the fd_locked_ioctl function in d…
- CVE-2018-7756RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit)…
- CVE-2018-7757Memory leak in the sas_smp_get_phy_events function in driver…
- CVE-2018-7759A buffer overflow vulnerability exists in Schneider Electric…
- CVE-2018-7760An authorization bypass vulnerability exists in Schneider El…
- CVE-2018-7761A vulnerability exists in the HTTP request parser in Schneid…
- CVE-2018-7762A vulnerability exists in the web services to process SOAP r…
- CVE-2018-7763The vulnerability exists within css.inc.php in Schneider Ele…
- CVE-2018-7764The vulnerability exists within runscript.php applet in Schn…
Are you affected by CVE-2018-7758?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
