Schneider-electric

Modicon M340

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 18.08.2025 06:58:15
  • Last modified 18.08.2025 20:16:28

CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.

  • EPSS 0.31%
  • Published 13.11.2024 05:15:25
  • Last modified 13.11.2024 17:01:16

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call...

  • EPSS 0.11%
  • Published 13.11.2024 05:15:20
  • Last modified 13.11.2024 17:01:16

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.

  • EPSS 0.06%
  • Published 13.11.2024 04:15:05
  • Last modified 13.11.2024 17:01:16

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of contr...

  • EPSS 1.1%
  • Published 04.04.2013 11:58:49
  • Last modified 11.04.2025 00:51:21

The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embeddi...

  • EPSS 0.54%
  • Published 04.04.2013 11:58:49
  • Last modified 11.04.2025 00:51:21

The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZilla FTP client.

  • EPSS 0.37%
  • Published 04.04.2013 11:58:48
  • Last modified 11.04.2025 00:51:21

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote at...