cbcvebase.
CVE-2013-0663
published 2013-04-04

CVE-2013-0663: Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and…

PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
5.96%
92.4th percentile
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.

Affected

9 ranges
VendorProductVersion rangeFixed in
schneider-electricmodicon_m340
schneider-electricmodicon_m340
schneider-electricmodicon_m340
schneider-electricmodicon_premium
schneider-electricmodicon_premium
schneider-electricmodicon_premium
schneider-electricmodicon_quantum_plc
schneider-electricmodicon_quantum_plc
schneider-electricmodicon_quantum_plc
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.