PT-2013-1323 · Schneider Electric · Modicon Quantum+2

Published

2013-05-15

·

Updated

2024-04-10

·

CVE-2020-7541

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Modicon M340 versions (affected versions not specified) Modicon Quantum versions (affected versions not specified) Modicon Premium versions (affected versions not specified)
Description The issue is related to errors in security mechanisms, which can be exploited to obtain configuration information of the SMTP server, including user logins and passwords, by sending a specially crafted HTTP request. This is a Direct Request ('Forced Browsing') vulnerability that could cause disclosure of sensitive data.
Recommendations For Modicon M340, consider restricting access to the web server to minimize the risk of exploitation. For Modicon Quantum, avoid using the web server until a patch is available. For Modicon Premium, restrict access to the communication modules to prevent sensitive data disclosure. As a temporary workaround, consider disabling the HTTP request handling functionality until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BDU:2020-05608
CVE-2020-7541

Affected Products

Modicon M340
Modicon Premium
Modicon Quantum