A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) (All Versions)
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01 | Patch Vendor Advisory |
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
History
21 Nov 2024, 05:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01 - Patch, Vendor Advisory |
10 Apr 2024, 12:28
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:schneider-electric:bmxp342020_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp342020_firmware:*:*:*:*:*:*:*:* |
First Time |
Schneider-electric modicon M340 Bmxp342020 Firmware
Schneider-electric modicon M340 Bmxp342020 |
10 Feb 2022, 06:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:schneider-electric:140noc78000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:bmxnoc0401:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:bmxnor0200h:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:140cpu65_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:tsxp57:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:bmxnor0200h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:140noe77111:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:140noc78000:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:tsxety5103_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:bmxnoc0401_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:140cpu65:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:bmxp342020_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:tsxety5103:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:tsxp57_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:bmxnoe01:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:bmxp342020:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:140noe77111_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:bmxnoe01_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:tsxety4103_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:tsxety4103:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.8 |
References | (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01 - Patch, Vendor Advisory |
04 Feb 2022, 23:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-02-04 23:15
Updated : 2024-11-21 05:37
NVD link : CVE-2020-7534
Mitre link : CVE-2020-7534
CVE.ORG link : CVE-2020-7534
JSON object : View
Products Affected
schneider-electric
- 140cpu65
- tsxety4103_firmware
- 140noc78000
- modicon_m340_bmxp342020
- 140noe77111_firmware
- tsxp57
- 140cpu65_firmware
- bmxnoe01_firmware
- tsxp57_firmware
- bmxnoe01
- bmxnor0200h
- bmxnoc0401_firmware
- tsxety4103
- tsxety5103_firmware
- 140noc78000_firmware
- bmxnoc0401
- tsxety5103
- bmxnor0200h_firmware
- modicon_m340_bmxp342020_firmware
- 140noe77111
CWE
CWE-352
Cross-Site Request Forgery (CSRF)