Out-of-Bounds Read Vulnerability in Modicon Controllers by Schneider Electric
CVE-2020-7562
8.1HIGH
Summary
An Out-of-Bounds Read vulnerability is present in the Web Server of specific Modicon controllers by Schneider Electric. This issue affects the Modicon M340, Modicon Quantum, and Modicon Premium along with their respective Communication Modules. When a specially crafted file is uploaded to the controller via FTP, it may lead to a segmentation fault or even a buffer overflow, potentially compromising the system integrity.
Affected Version(s)
Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details)
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved