PT-2015-2899 · Schneider Electric+1 · Modicon M340 Plc+1

David Atch

·

Published

2015-12-21

·

Updated

2024-04-10

·

CVE-2015-7937

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices (affected versions not specified)
Description The issue is caused by a stack-based buffer overflow in the GoAhead Web Server, allowing remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data. This can be exploited by sending a long password, which can lead to the execution of arbitrary code.
Recommendations For Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices, consider restricting access to the HTTP Basic Authentication feature until a fix is available. As a temporary workaround, consider limiting the length of passwords to prevent exploitation of the buffer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-12266
CVE-2015-7937

Affected Products

Goahead Web Server
Modicon M340 Plc