Remote Code Execution Vulnerability in Schneider Electric PLC Modules
CVE-2013-0664
Currently unrated
Summary
The FactoryCast service in certain Schneider Electric PLC modules is vulnerable to remote code execution due to improper handling of Modbus messages embedded within SOAP HTTP POST requests. Authenticated remote users can exploit this vulnerability, leading to arbitrary code execution. This situation underscores the importance of securing industrial control systems and ensuring all service interfaces are properly validated to prevent unauthorized access and control.
References
Timeline
Vulnerability Reserved
Vulnerability published