Schneider-electric ≫ Modicon M340 Bmxp3420302 Firmware
28 Schwachstellen gefunden.
CVE-2020-7542
- EPSS 0.39%
- Veröffentlicht 11.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:20
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of se...
CVE-2020-7541
- EPSS 0.31%
- Veröffentlicht 11.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:20
A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could...
CVE-2020-7540
- EPSS 0.31%
- Veröffentlicht 11.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:20
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), ...
CVE-2020-7539
- EPSS 0.32%
- Veröffentlicht 11.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:20
A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected vers...
CVE-2020-7536
- EPSS 0.48%
- Veröffentlicht 11.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:20
A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4 BMXNOE0110 (H) versions prio...
CVE-2020-7535
- EPSS 0.43%
- Veröffentlicht 11.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:19
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules...
CVE-2020-7533
- EPSS 0.24%
- Veröffentlicht 01.12.2020 15:15:12
- Zuletzt bearbeitet 10.06.2025 08:15:21
CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.
CVE-2019-6855
- EPSS 0.19%
- Veröffentlicht 06.01.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:47:17
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause ...
CVE-2015-6462
- EPSS 0.58%
- Veröffentlicht 21.03.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:35:00
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BM...
CVE-2015-6461
- EPSS 0.31%
- Veröffentlicht 21.03.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:35:00
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H P...