Schneider-Electric Modicon M340 BMX NOE 0100

CPE Details

Schneider-Electric Modicon M340 BMX NOE 0100
-
2020-12-01
13h55 +00:00
2021-05-11
15h04 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:h:schneider-electric:modicon_m340_bmx_noe_0100:-:*:*:*:*:*:*:*

Informations

Vendor

schneider-electric

Product

modicon_m340_bmx_noe_0100

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-7562 2020-11-18 12h54 +00:00 A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.
8.1
High
CVE-2020-7564 2020-11-18 12h51 +00:00 A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.
8.8
High
CVE-2020-7563 2020-11-18 12h50 +00:00 A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.
8.8
High
CVE-2013-2763 2013-04-04 10h00 +00:00 The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.
5