A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) (All Versions)

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
140cpu65 Subscribe
140cpu65 Firmware Subscribe
140noc78000 Subscribe
140noc78000 Firmware Subscribe
140noe77111 Subscribe
140noe77111 Firmware Subscribe
Bmxnoc0401 Subscribe
Bmxnoc0401 Firmware Subscribe
Bmxnoe01 Subscribe
Bmxnoe01 Firmware Subscribe
Bmxnor0200h Subscribe
Bmxnor0200h Firmware Subscribe
Modicon M340 Bmxp342020 Subscribe
Modicon M340 Bmxp342020 Firmware Subscribe
Tsxety4103 Subscribe
Tsxety4103 Firmware Subscribe
Tsxety5103 Subscribe
Tsxety5103 Firmware Subscribe
Tsxp57 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T09:33:19.804Z

Reserved: 2020-01-21T00:00:00

Link: CVE-2020-7534

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-04T23:15:10.390

Modified: 2024-11-21T05:37:19.763

Link: CVE-2020-7534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses