Schneider-electric
Schneider-electric Modicon M340 Bmxp342020 Firmware: vulnerabilidades y CVE
Schneider-electric Modicon M340 Bmxp342020 Firmware tiene 32 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses0
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-6408 | Alta (8.1) | 0.32% | — | 14 feb 2024 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when… |
| CVE-2021-22786 | Alta (7.5) | 0.63% | — | 1 feb 2023 | A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products:… |
| CVE-2022-45789 | Crítica (9.8) | 1.5% | — | 31 ene 2023 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products:… |
| CVE-2022-45788 | Crítica (9.8) | 1.2% | — | 30 ene 2023 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is… |
| CVE-2022-0222 | Alta (7.5) | 0.61% | — | 22 nov 2022 | A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon… |
| CVE-2022-37300 | Crítica (9.8) | 0.77% | — | 12 sept 2022 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products:… |
| CVE-2021-22788 | Alta (7.5) | 1.0% | — | 11 feb 2022 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34… |
| CVE-2021-22787 | Alta (7.5) | 1.0% | — | 11 feb 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product:… |
| CVE-2021-22785 | Alta (7.5) | 0.96% | — | 11 feb 2022 | A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device.… |
| CVE-2020-7534 | Alta (8.8) | 0.36% | — | 4 feb 2022 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in.… |
| CVE-2021-22779 | Crítica (9.1) | 1.0% | — | 14 jul 2021 | Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process… |
| CVE-2020-7549 | Media (5.3) | 1.1% | — | 11 dic 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see… |
| CVE-2020-7543 | Alta (7.5) | 1.3% | — | 11 dic 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected… |
| CVE-2020-7542 | Alta (7.5) | 1.3% | — | 11 dic 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected… |
| CVE-2020-7541 | Media (5.3) | 0.91% | — | 11 dic 2020 | A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for… |
| CVE-2020-7540 | Crítica (9.8) | 2.3% | — | 11 dic 2020 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security… |
| CVE-2020-7539 | Alta (7.5) | 1.2% | — | 11 dic 2020 | A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security… |
| CVE-2020-7537 | Alta (7.5) | 1.4% | — | 11 dic 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected… |
| CVE-2020-7536 | Alta (7.5) | 1.2% | — | 11 dic 2020 | A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to… |
| CVE-2020-7535 | Alta (7.5) | 1.5% | — | 11 dic 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and… |
| CVE-2019-6855 | Alta (7.3) | 0.95% | — | 6 ene 2020 | Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions… |
| CVE-2015-6462 | Media (5.4) | 0.56% | — | 21 mar 2019 | Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110,… |
| CVE-2015-6461 | Media (5.4) | 0.87% | — | 21 mar 2019 | Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302,… |
| CVE-2018-7762 | Alta (7.5) | 1.3% | — | 18 abr 2018 | A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow result in a buffer overflow. |
| CVE-2018-7761 | Crítica (9.8) | 2.1% | — | 18 abr 2018 | A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow arbitrary code execution. |
| CVE-2018-7760 | Crítica (9.8) | 1.5% | — | 18 abr 2018 | An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization. |
| CVE-2018-7759 | Alta (7.5) | 1.3% | — | 18 abr 2018 | A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. The buffer overflow vulnerability is caused by the length of the source string specified… |
| CVE-2018-7242 | Crítica (9.8) | 1.9% | — | 18 abr 2018 | Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the… |
| CVE-2018-7241 | Crítica (9.8) | 3.7% | — | 18 abr 2018 | Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. |
| CVE-2017-6017 | Alta (7.5) | 4.8% | — | 30 jun 2017 | A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020,… |
Otros productos de Schneider-electric
Struxureware Data Center Expert · 49Interactive Graphical Scada System · 43Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Ecostruxure Control Expert · 26Modicon M340 Bmxp342000 Firmware · 25Modicon Quantum Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Easergy T300 Firmware · 24U.motion Builder · 24