Description
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.
Published: 2014-10-03
Score: 10 Critical
EPSS: 18.9% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Please see Schneider Electric’s vulnerability disclosure (SEVD-2014-260-01)Schneider Electric Vulnerability Disclosure – Modicon Ethernet Comm Modules - SEVD-2014-260-01 - http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2014-260-01 . for more detailed information on which product part numbers are affected, as well as the complete list of which devices have released firmware updates available. This vulnerability disclosure can be downloaded at the following URL:  http://www.schneider-electric.com/ww/en/download/


Vendor Workaround

Search downloads for SEVD-14-260-01, then keyword SEVD-14-260-01 to download the vulnerability disclosure. This URL site can also be used to download firmware updates identified in the vulnerability disclosure. Schneider Electric also recommends the following measures to mitigate the vulnerability for the remaining affected devices: * Use a deep packet inspection firewall to prevent HTTP requests to the product that contains traversals in the URL. * Disable Port 80 (HTTP) on modules where it is possible. * Block Port 80 in firewalls to these devices, except for trusted devices. Please contact Schneider Electric Customer Care Center for more information.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2014-0785 Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.
History

Tue, 26 Aug 2025 00:00:00 +0000


Subscriptions

Schneider-electric 171ccc96020 171ccc96020 Firmware 171ccc96020c 171ccc96020c Firmware 171ccc96030 171ccc96030 Firmware 171ccc96030c 171ccc96030c Firmware 171ccc98020 171ccc98020 Firmware 171ccc98030 171ccc98030 Firmware Modicon M340 Bmxnoc0401 Modicon M340 Bmxnoc0401 Firmware Modicon M340 Bmxnoe0100 Modicon M340 Bmxnoe0100 Firmware Modicon M340 Bmxnoe0110 Modicon M340 Bmxnoe0110 Firmware Modicon M340 Bmxnoe0110h Modicon M340 Bmxnoe0110h Firmware Modicon M340 Bmxnor0200h Modicon M340 Bmxnor0200h Firmware Modicon M340 Bmxp342020 Modicon M340 Bmxp342020 Firmware Modicon M340 Bmxp342020h Modicon M340 Bmxp342020h Firmware Modicon M340 Bmxp342030 Modicon M340 Bmxp3420302 Modicon M340 Bmxp3420302 Firmware Modicon M340 Bmxp3420302h Modicon M340 Bmxp3420302h Firmware Modicon M340 Bmxp342030 Firmware Modicon M340 Bmxp342030h Modicon M340 Bmxp342030h Firmware Modicon M580 Bmxnoc0402 Modicon M580 Bmxnoc0402 Firmware Stbnic2212 Stbnic2212 Firmware Stbnip2212 Stbnip2212 Firmware Tsxetc0101 Tsxetc0101 Firmware Tsxetc100 Tsxetc100 Firmware Tsxety110ws Tsxety110ws Firmware Tsxety110wsc Tsxety110wsc Firmware Tsxety4103 Tsxety4103 Firmware Tsxety4103c Tsxety4103c Firmware Tsxety5103 Tsxety5103 Firmware Tsxety5103c Tsxety5103c Firmware Tsxetz410 Tsxetz410 Firmware Tsxetz510 Tsxetz510 Firmware Tsxntp100 Tsxntp100 Firmware Tsxp571634m Tsxp571634m Firmware Tsxp572634m Tsxp572634m Firmware Tsxp573623mc Tsxp573623mc Firmware Tsxp573634m Tsxp573634m Firmware Tsxp574634m Tsxp574634m Firmware Tsxp574823am Tsxp574823am Firmware Tsxp574823m Tsxp574823m Firmware Tsxp574823mc Tsxp574823mc Firmware Tsxp575634m Tsxp575634m Firmware Tsxp576634m Tsxp576634m Firmware Tsxwmy100 Tsxwmy100 Firmware Tsxwmy100c Tsxwmy100c Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-08-25T23:45:03.684Z

Reserved: 2014-01-02T00:00:00.000Z

Link: CVE-2014-0754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-10-03T18:55:06.017

Modified: 2025-08-26T00:15:30.757

Link: CVE-2014-0754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses