PT-2020-6346 · Schneider Electric · Modicon M340+3
Published
2020-10-13
·
Updated
2025-06-10
·
CVE-2020-7533
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Modicon M340 versions (affected versions not specified)
Modicon Quantum versions (affected versions not specified)
Modicon Premium Legacy versions (affected versions not specified)
Communication Modules versions (affected versions not specified)
Description
A Credentials Management issue exists which could cause the execution of commands on the web server without authentication when sending specially crafted HTTP requests. This could allow a remote attacker to execute arbitrary commands using HTTP requests.
Recommendations
For Modicon M340, check the security notification for specific version information and follow the recommended update or patch instructions.
For Modicon Quantum, check the security notification for specific version information and follow the recommended update or patch instructions.
For Modicon Premium Legacy, check the security notification for specific version information and follow the recommended update or patch instructions.
For Communication Modules, check the security notification for specific version information and follow the recommended update or patch instructions.
As a temporary workaround, consider restricting access to the web server to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Communication Modules
Modicon M340
Modicon Premium Legacy
Modicon Quantum