A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) (All Versions)
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
140cpu65
Subscribe
140cpu65 Firmware
Subscribe
140noc78000
Subscribe
140noc78000 Firmware
Subscribe
140noe77111
Subscribe
140noe77111 Firmware
Subscribe
Bmxnoc0401
Subscribe
Bmxnoc0401 Firmware
Subscribe
Bmxnoe01
Subscribe
Bmxnoe01 Firmware
Subscribe
Bmxnor0200h
Subscribe
Bmxnor0200h Firmware
Subscribe
Modicon M340 Bmxp342020
Subscribe
Modicon M340 Bmxp342020 Firmware
Subscribe
Tsxety4103
Subscribe
Tsxety4103 Firmware
Subscribe
Tsxety5103
Subscribe
Tsxety5103 Firmware
Subscribe
Tsxp57
Subscribe
Tsxp57 Firmware
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T09:33:19.804Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7534
No data.
Status : Modified
Published: 2022-02-04T23:15:10.390
Modified: 2024-11-21T05:37:19.763
Link: CVE-2020-7534
No data.
OpenCVE Enrichment
No data.
Weaknesses