Schneider-electric
Schneider-electric Tsxety5103 Firmware: vulnerabilidades y CVE
Schneider-electric Tsxety5103 Firmware tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-22788 | Alta (7.5) | 1.0% | — | 11 feb 2022 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34… |
| CVE-2021-22787 | Alta (7.5) | 1.0% | — | 11 feb 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product:… |
| CVE-2021-22785 | Alta (7.5) | 0.96% | — | 11 feb 2022 | A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device.… |
| CVE-2020-7534 | Alta (8.8) | 0.36% | — | 4 feb 2022 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in.… |
| CVE-2020-7549 | Media (5.3) | 1.1% | — | 11 dic 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see… |
| CVE-2020-7541 | Media (5.3) | 0.91% | — | 11 dic 2020 | A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for… |
| CVE-2020-7540 | Crítica (9.8) | 2.3% | — | 11 dic 2020 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security… |
| CVE-2020-7539 | Alta (7.5) | 1.2% | — | 11 dic 2020 | A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security… |
| CVE-2020-7535 | Alta (7.5) | 1.5% | — | 11 dic 2020 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and… |
| CVE-2020-7533 | Crítica (9.8) | 2.3% | — | 1 dic 2020 | CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests. |
| CVE-2014-0754 | Alta (10) | 9.5% | — | 3 oct 2014 | Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100… |
Otros productos de Schneider-electric
Struxureware Data Center Expert · 49Interactive Graphical Scada System · 43Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp342020 Firmware · 32Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Ecostruxure Control Expert · 26Modicon Quantum Firmware · 25Modicon M340 Bmxp342000 Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Easergy T300 Firmware · 24