CVE-2018-7758

UnknownEPSS 0.63%

Last modified

CVE-2018-7758 is a vulnerability of currently unknown severity. A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.. EPSS estimates a 0.63% chance of exploitation in the next 30 days.

Description

A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.

Metrics

EPSS Probability
0.63%

45.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Schneider-ElectricMicom P141 FirmwareAll versions
Schneider-ElectricMicom P142 FirmwareAll versions
Schneider-ElectricMicom P143 FirmwareAll versions
Schneider-ElectricMicom P145 FirmwareAll versions
Schneider-ElectricMicom P642 FirmwareAll versions
Schneider-ElectricMicom P643 FirmwareAll versions
Schneider-ElectricMicom P645 FirmwareAll versions
Schneider-ElectricMicom P849 FirmwareAll versions
Schneider-ElectricMicom P746 FirmwareAll versions
Schneider-ElectricMicom P841a FirmwareAll versions
Schneider-ElectricMicom P841b FirmwareAll versions
Schneider-ElectricMicom P443 FirmwareAll versions
Schneider-ElectricMicom P445 FirmwareAll versions
Schneider-ElectricMicom P446 FirmwareAll versions
Schneider-ElectricMicom P441 FirmwareAll versions
Schneider-ElectricMicom P442 FirmwareAll versions
Schneider-ElectricMicom P444 FirmwareAll versions
Schneider-ElectricMicom P541 FirmwareAll versions
Schneider-ElectricMicom P542 FirmwareAll versions
Schneider-ElectricMicom P543 FirmwareAll versions
Schneider-ElectricMicom P544 FirmwareAll versions
Schneider-ElectricMicom P545 FirmwareAll versions
Schneider-ElectricMicom P546 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-7758?
A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.
How severe is CVE-2018-7758?
Severity scoring for CVE-2018-7758 is pending analysis. The EPSS model estimates a 0.63% probability of exploitation in the next 30 days.
How do I fix CVE-2018-7758?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-7758?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST