V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-7539
CVE
High

A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modico…

CVSS
7.5
High
EPSS
0.01
p62
Published
2020-01-01
Updated
2020-01-01
Description

A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause a denial of service vulnerability when a specially crafted packet is sent to the controller over HTTP.

Tags · CWE
Pre-auth
CWE-754
Affected products
140cpu65150_firmware140noc77101_firmware140noc78000_firmware140noc78100_firmware140noe77111_firmwareBmxnoc0401_firmwareBmxnoe0100_firmwareBmxnoe0110_firmwareModicon_m340_bmxp341000_firmwareModicon_m340_bmxp342000_firmwareModicon_m340_bmxp3420102_firmwareModicon_m340_bmxp3420102cl_firmwareModicon_m340_bmxp342020_firmwareModicon_m340_bmxp3420302_firmwareModicon_m340_bmxp3420302cl_firmwareTsxety4103_firmwareTsxety5103_firmwareTsxp574634_firmwareTsxp575634_firmwareTsxp576634_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.011 · p62
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
140cpu65150_firmware*Tracked
140noc77101_firmware*Tracked
140noc78000_firmware*Tracked
140noc78100_firmware*Tracked
140noe77111_firmware*Tracked
bmxnoc0401_firmware*Tracked
bmxnoe0100_firmware*Tracked
bmxnoe0110_firmware*Tracked
modicon_m340_bmxp341000_firmware*Tracked
modicon_m340_bmxp342000_firmware*Tracked
modicon_m340_bmxp3420102_firmware*Tracked
modicon_m340_bmxp3420102cl_firmware*Tracked
modicon_m340_bmxp342020_firmware*Tracked
modicon_m340_bmxp3420302_firmware*Tracked
modicon_m340_bmxp3420302cl_firmware*Tracked
tsxety4103_firmware*Tracked
tsxety5103_firmware*Tracked
tsxp574634_firmware*Tracked
tsxp575634_firmware*Tracked
tsxp576634_firmware*Tracked
Source databases
CVE
Related vulnerabilities