Schneider-electric

Modicon M340 Bmxp342020 Firmware

32 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Published 14.02.2024 17:15:11
  • Last modified 23.01.2025 19:39:42

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle att...

  • EPSS 0.18%
  • Published 01.02.2023 04:15:08
  • Last modified 21.11.2024 05:50:39

A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP...

  • EPSS 0.06%
  • Published 31.01.2023 06:15:07
  • Last modified 21.11.2024 07:29:43

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All V...

  • EPSS 0.29%
  • Published 30.01.2023 13:15:09
  • Last modified 21.11.2024 07:29:43

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Aff...

  • EPSS 0.21%
  • Published 22.11.2022 13:15:10
  • Last modified 21.11.2024 06:38:10

A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior ...

  • EPSS 0.54%
  • Published 12.09.2022 18:15:08
  • Last modified 21.11.2024 07:14:42

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Includ...

  • EPSS 1.46%
  • Published 11.02.2022 18:15:09
  • Last modified 21.11.2024 05:50:40

A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Mod...

  • EPSS 0.43%
  • Published 11.02.2022 18:15:09
  • Last modified 21.11.2024 05:50:40

A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions p...

  • EPSS 0.32%
  • Published 11.02.2022 18:15:08
  • Last modified 21.11.2024 05:50:39

A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs:...

  • EPSS 0.18%
  • Published 04.02.2022 23:15:10
  • Last modified 21.11.2024 05:37:19

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs:...