CWE-287: Improper Authentication vulnerability exists which could cause the execution of
commands on the webserver without authentication when sending specially crafted HTTP
requests.
commands on the webserver without authentication when sending specially crafted HTTP
requests.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
140cpu65260
Subscribe
140cpu65260 Firmware
Subscribe
140noc77101
Subscribe
140noc77101 Firmware
Subscribe
140noc78000
Subscribe
140noc78000 Firmware
Subscribe
140noe77111
Subscribe
140noe77111 Firmware
Subscribe
Bmxnoc0401
Subscribe
Bmxnoc0401 Firmware
Subscribe
Bmxnoe0100
Subscribe
Bmxnoe0100 Firmware
Subscribe
Bmxnoe0110
Subscribe
Bmxnoe0110 Firmware
Subscribe
Modicon M340 Bmxp341000
Subscribe
Modicon M340 Bmxp341000 Firmware
Subscribe
Modicon M340 Bmxp342000
Subscribe
Modicon M340 Bmxp342000 Firmware
Subscribe
Modicon M340 Bmxp3420102
Subscribe
Modicon M340 Bmxp3420102 Firmware
Subscribe
Modicon M340 Bmxp3420302
Subscribe
Modicon M340 Bmxp3420302 Firmware
Subscribe
Tsxety4103
Subscribe
Tsxety4103 Firmware
Subscribe
Tsxety5103
Subscribe
Tsxety5103 Firmware
Subscribe
Tsxp574634
Subscribe
Tsxp574634 Firmware
Subscribe
Tsxp575634
Subscribe
Tsxp575634 Firmware
Subscribe
Tsxp576634
Subscribe
Tsxp576634 Firmware
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 10 Jun 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-255 |
Tue, 10 Jun 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A CWE-255: Credentials Management vulnerability exists in Web Server on Modicon M340, Modicon Quantum and ModiconPremium Legacy offers and their Communication Modules (see security notification for version information) which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests. | CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests. |
| Weaknesses | CWE-287 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-06-10T08:02:15.209Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7533
No data.
Status : Modified
Published: 2020-12-01T15:15:12.190
Modified: 2025-06-10T08:15:21.423
Link: CVE-2020-7533
No data.
OpenCVE Enrichment
No data.
Weaknesses