A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Modicon M340 Bmx Noc 0401
Subscribe
Modicon M340 Bmx Noc 0401 Firmware
Subscribe
Modicon M340 Bmx Noe 0100
Subscribe
Modicon M340 Bmx Noe 0100 Firmware
Subscribe
Modicon M340 Bmx Noe 0100h
Subscribe
Modicon M340 Bmx Noe 0100h Firmware
Subscribe
Modicon M340 Bmx Noe 0110
Subscribe
Modicon M340 Bmx Noe 0110 Firmware
Subscribe
Modicon M340 Bmx Noe 0110h
Subscribe
Modicon M340 Bmx Noe 0110h Firmware
Subscribe
Modicon M340 Bmx Nor 0200h
Subscribe
Modicon M340 Bmx Nor 0200h Firmware
Subscribe
Modicon M340 Bmx P34-2010
Subscribe
Modicon M340 Bmx P34-2010 Firmware
Subscribe
Modicon M340 Bmx P34-2030
Subscribe
Modicon M340 Bmx P34-2030 Firmware
Subscribe
Modicon Quantum 140cpu65150
Subscribe
Modicon Quantum 140cpu65150 Firmware
Subscribe
Modicon Quantum 140cpu65150c
Subscribe
Modicon Quantum 140cpu65150c Firmware
Subscribe
Modicon Quantum 140cpu65160
Subscribe
Modicon Quantum 140cpu65160 Firmware
Subscribe
Modicon Quantum 140cpu65160c
Subscribe
Modicon Quantum 140cpu65160c Firmware
Subscribe
Modicon Quantum 140noc78100
Subscribe
Modicon Quantum 140noc78100 Firmware
Subscribe
Modicon Quantum 140noe77101
Subscribe
Modicon Quantum 140noe77101 Firmware
Subscribe
Modicon Quantum 140noe77111
Subscribe
Modicon Quantum 140noe77111 Firmware
Subscribe
Modicon Tsxety4103
Subscribe
Modicon Tsxety4103 Firmware
Subscribe
Modicon Tsxety5103
Subscribe
Modicon Tsxety5103 Firmware
Subscribe
Modicon Tsxp574634
Subscribe
Modicon Tsxp574634 Firmware
Subscribe
Modicon Tsxp575634
Subscribe
Modicon Tsxp575634 Firmware
Subscribe
Modicon Tsxp576634
Subscribe
Modicon Tsxp576634 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28687 | A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.se.com/ww/en/download/document/SEVD-2020-315-01/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T09:33:19.944Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7562
No data.
Status : Modified
Published: 2020-11-18T14:15:12.377
Modified: 2024-11-21T05:37:22.960
Link: CVE-2020-7562
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD