Description
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) (All Versions)
Published: 2022-02-04
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Schneider-electric 140cpu65 140cpu65 Firmware 140noc78000 140noc78000 Firmware 140noe77111 140noe77111 Firmware Bmxnoc0401 Bmxnoc0401 Firmware Bmxnoe01 Bmxnoe01 Firmware Bmxnor0200h Bmxnor0200h Firmware Modicon M340 Bmxp342020 Modicon M340 Bmxp342020 Firmware Tsxety4103 Tsxety4103 Firmware Tsxety5103 Tsxety5103 Firmware Tsxp57 Tsxp57 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T09:33:19.804Z

Reserved: 2020-01-21T00:00:00.000Z

Link: CVE-2020-7534

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-04T23:15:10.390

Modified: 2024-11-21T05:37:19.763

Link: CVE-2020-7534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses