V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-7542
CVE
High

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modi…

CVSS
7.5
High
EPSS
0.01
p66
Published
2020-01-01
Updated
2020-01-01
Description

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.

Tags · CWE
Pre-auth
CWE-754
Affected products
140cpu65150_firmwareModicon_m340_bmxp341000_firmwareModicon_m340_bmxp342000_firmwareModicon_m340_bmxp3420102_firmwareModicon_m340_bmxp3420102cl_firmwareModicon_m340_bmxp342020_firmwareModicon_m340_bmxp3420302_firmwareModicon_m340_bmxp3420302cl_firmwareModicon_m580_bmep581020_firmwareModicon_m580_bmep582020_firmwareModicon_m580_bmep582040_firmwareModicon_m580_bmep583020_firmwareModicon_m580_bmep583040_firmwareModicon_m580_bmep584020_firmwareModicon_m580_bmep584040_firmwareModicon_m580_bmep585040_firmwareModicon_m580_bmep586040_firmwareTsxp574634_firmwareTsxp575634_firmwareTsxp576634_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.013 · p66
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
140cpu65150_firmware*Tracked
modicon_m340_bmxp341000_firmware*Tracked
modicon_m340_bmxp342000_firmware*Tracked
modicon_m340_bmxp3420102_firmware*Tracked
modicon_m340_bmxp3420102cl_firmware*Tracked
modicon_m340_bmxp342020_firmware*Tracked
modicon_m340_bmxp3420302_firmware*Tracked
modicon_m340_bmxp3420302cl_firmware*Tracked
modicon_m580_bmep581020_firmware*Tracked
modicon_m580_bmep582020_firmware*Tracked
modicon_m580_bmep582040_firmware*Tracked
modicon_m580_bmep583020_firmware*Tracked
modicon_m580_bmep583040_firmware*Tracked
modicon_m580_bmep584020_firmware*Tracked
modicon_m580_bmep584040_firmware*Tracked
modicon_m580_bmep585040_firmware*Tracked
modicon_m580_bmep586040_firmware*Tracked
tsxp574634_firmware*Tracked
tsxp575634_firmware*Tracked
tsxp576634_firmware*Tracked
Source databases
CVE