Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.00516.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Modicon M340 Bmx Noc 0401
Subscribe
Modicon M340 Bmx Noc 0401 Firmware
Subscribe
Modicon M340 Bmx Noe 0100
Subscribe
Modicon M340 Bmx Noe 0100 Firmware
Subscribe
Modicon M340 Bmx Noe 0100h
Subscribe
Modicon M340 Bmx Noe 0100h Firmware
Subscribe
Modicon M340 Bmx Noe 0110
Subscribe
Modicon M340 Bmx Noe 0110 Firmware
Subscribe
Modicon M340 Bmx Noe 0110h
Subscribe
Modicon M340 Bmx Noe 0110h Firmware
Subscribe
Modicon M340 Bmx Nor 0200h
Subscribe
Modicon M340 Bmx Nor 0200h Firmware
Subscribe
Modicon M340 Bmx P34-2010
Subscribe
Modicon M340 Bmx P34-2010 Firmware
Subscribe
Modicon M340 Bmx P34-2030
Subscribe
Modicon M340 Bmx P34-2030 Firmware
Subscribe
Modicon Quantum 140cpu65150
Subscribe
Modicon Quantum 140cpu65150 Firmware
Subscribe
Modicon Quantum 140cpu65150c
Subscribe
Modicon Quantum 140cpu65150c Firmware
Subscribe
Modicon Quantum 140cpu65160
Subscribe
Modicon Quantum 140cpu65160 Firmware
Subscribe
Modicon Quantum 140cpu65160c
Subscribe
Modicon Quantum 140cpu65160c Firmware
Subscribe
Modicon Quantum 140noc78100
Subscribe
Modicon Quantum 140noc78100 Firmware
Subscribe
Modicon Quantum 140noe77101
Subscribe
Modicon Quantum 140noe77101 Firmware
Subscribe
Modicon Quantum 140noe77111
Subscribe
Modicon Quantum 140noe77111 Firmware
Subscribe
Modicon Tsxety4103
Subscribe
Modicon Tsxety4103 Firmware
Subscribe
Modicon Tsxety5103
Subscribe
Modicon Tsxety5103 Firmware
Subscribe
Modicon Tsxp574634
Subscribe
Modicon Tsxp574634 Firmware
Subscribe
Modicon Tsxp575634
Subscribe
Modicon Tsxp575634 Firmware
Subscribe
Modicon Tsxp576634
Subscribe
Modicon Tsxp576634 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28687 | A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.se.com/ww/en/download/document/SEVD-2020-315-01/ |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T09:33:19.944Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7562
No data.
Status : Modified
Published: 2020-11-18T14:15:12.377
Modified: 2024-11-21T05:37:22.960
Link: CVE-2020-7562
No data.
OpenCVE Enrichment
No data.
EUVD