Credentials Management Vulnerability in Modicon Web Servers by Schneider Electric
CVE-2020-7533

9.8CRITICAL

Summary

A credentials management vulnerability exists in the web server component of Schneider Electric's Modicon M340, Modicon Quantum, and Modicon Premium products. This weakness allows attackers to execute commands on the web server without the need for authentication by sending specially crafted HTTP requests. This represents a significant risk, as it can lead to unauthorized access and manipulation of the device configurations.

Affected Version(s)

Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see security notification for version information) Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see security notification for version information)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.