PT-2020-6346 · Schneider Electric · Modicon M340+3

Published

2020-10-13

·

Updated

2025-06-10

·

CVE-2020-7533

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Modicon M340 versions (affected versions not specified) Modicon Quantum versions (affected versions not specified) Modicon Premium Legacy versions (affected versions not specified) Communication Modules versions (affected versions not specified)
Description A Credentials Management issue exists which could cause the execution of commands on the web server without authentication when sending specially crafted HTTP requests. This could allow a remote attacker to execute arbitrary commands using HTTP requests.
Recommendations For Modicon M340, check the security notification for specific version information and follow the recommended update or patch instructions. For Modicon Quantum, check the security notification for specific version information and follow the recommended update or patch instructions. For Modicon Premium Legacy, check the security notification for specific version information and follow the recommended update or patch instructions. For Communication Modules, check the security notification for specific version information and follow the recommended update or patch instructions. As a temporary workaround, consider restricting access to the web server to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-04272
CVE-2020-7533

Affected Products

Communication Modules
Modicon M340
Modicon Premium Legacy
Modicon Quantum