CVE-2013-2761

CWE-119Buffer Overflow3 documents3 sources
Severity
4.0MEDIUM
EPSS
0.4%
top 42.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateMay 17

Description

The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZilla FTP client.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

NVDschneider-electric/modicon_m340bmxnoe01xx, bmxp3420xx+1

🔴Vulnerability Details

2
GHSA
GHSA-jv4v-gw8f-j23r: The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via cra2022-05-17
CVEList
CVE-2013-2761: The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via cra2013-04-04
CVE-2013-2761 (MEDIUM CVSS 4) | The Schneider Electric M340 BMXNOE0 | cvebase.io