PT-2022-6599 · Schneider Electric · Modicon Quantum Cpu+4
Published
2022-01-11
·
Updated
2024-04-10
·
CVE-2020-7534
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Modicon M340 CPUs version all
Modicon Quantum CPUs with integrated Ethernet version all
Modicon Premium CPUs with integrated Ethernet version all
Modicon M340 ethernet modules versions BMXNOC0401, BMXNOE01, BMXNOR0200H
Modicon Quantum and Premium factory cast communication modules versions 140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103
Description
A Cross-Site Request Forgery (CSRF) issue exists on the web server used, potentially causing a leak of sensitive data or unauthorized actions during the time the user is logged in. The vulnerability can be exploited by a remote attacker to gain access to confidential data.
Recommendations
For Modicon M340 CPUs, consider disabling access to the web server interface until a fix is available.
For Modicon Quantum CPUs with integrated Ethernet, restrict access to the web server during user login to minimize the risk of exploitation.
For Modicon Premium CPUs with integrated Ethernet, avoid using the web server for sensitive operations until the issue is resolved.
For Modicon M340 ethernet modules, restrict access to the modules to prevent unauthorized actions.
For Modicon Quantum and Premium factory cast communication modules, consider disabling the communication modules until a patch is available.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modicon M340 Cpu
Modicon M340 Ethernet Modules
Modicon Premium Cpu
Modicon Quantum Cpu
Modicon Quantum/Premium Factory Cast Communication Modules