Schneider-electric ≫ Modicon M340 Bmxp342020 Firmware
32 Schwachstellen gefunden.
CVE-2023-6408
- EPSS 0.16%
- Veröffentlicht 14.02.2024 17:15:11
- Zuletzt bearbeitet 23.01.2025 19:39:42
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle att...
CVE-2021-22786
- EPSS 0.18%
- Veröffentlicht 01.02.2023 04:15:08
- Zuletzt bearbeitet 21.11.2024 05:50:39
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP...
CVE-2022-45789
- EPSS 0.06%
- Veröffentlicht 31.01.2023 06:15:07
- Zuletzt bearbeitet 21.11.2024 07:29:43
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All V...
CVE-2022-45788
- EPSS 0.29%
- Veröffentlicht 30.01.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:29:43
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Aff...
CVE-2022-0222
- EPSS 0.21%
- Veröffentlicht 22.11.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 06:38:10
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior ...
CVE-2022-37300
- EPSS 0.54%
- Veröffentlicht 12.09.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:14:42
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Includ...
CVE-2021-22788
- EPSS 1.46%
- Veröffentlicht 11.02.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:50:40
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Mod...
CVE-2021-22787
- EPSS 0.43%
- Veröffentlicht 11.02.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:50:40
A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions p...
CVE-2021-22785
- EPSS 0.32%
- Veröffentlicht 11.02.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:50:39
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs:...
CVE-2020-7534
- EPSS 0.18%
- Veröffentlicht 04.02.2022 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:19
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs:...