PT-2015-2899 · Schneider Electric+1 · Modicon M340 Plc+1
David Atch
·
Published
2015-12-21
·
Updated
2024-04-10
·
CVE-2015-7937
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices (affected versions not specified)
Description
The issue is caused by a stack-based buffer overflow in the GoAhead Web Server, allowing remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data. This can be exploited by sending a long password, which can lead to the execution of arbitrary code.
Recommendations
For Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices, consider restricting access to the HTTP Basic Authentication feature until a fix is available.
As a temporary workaround, consider limiting the length of passwords to prevent exploitation of the buffer overflow.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Goahead Web Server
Modicon M340 Plc