A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-28689 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-315-01/ |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T09:33:19.905Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7564

No data.

Status : Modified
Published: 2020-11-18T14:15:13.363
Modified: 2024-11-21T05:37:23.213
Link: CVE-2020-7564

No data.

No data.