CVE-2018-8872
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 2.3%
from disclosure to weapon
Published on NVDMay 4
VulnCheckJan 12
exploitation probability
2.3%top 19% of all CVEs
observed exploitation
yesVulnCheck
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.
Affected products
Schneider Electric · Triconex Tricon