CVE-2020-7537
published 2020-12-11CVE-2020-7537: A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum &…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.38%
69.0th percentile
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | modicon_m340_bmxp341000_firmware | < 3.30 | 3.30 |
| schneider-electric | modicon_m340_bmxp342000_firmware | < 3.30 | 3.30 |
| schneider-electric | modicon_m340_bmxp3420102_firmware | < 3.30 | 3.30 |
| schneider-electric | modicon_m340_bmxp3420102cl_firmware | < 3.30 | 3.30 |
| schneider-electric | modicon_m340_bmxp342020_firmware | < 3.30 | 3.30 |
| schneider-electric | modicon_m340_bmxp3420302_firmware | < 3.30 | 3.30 |
| schneider-electric | modicon_m340_bmxp3420302cl_firmware | < 3.30 | 3.30 |
| schneider-electric | modicon_m580_bmep581020_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep582020_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep582040_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep583020_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep583040_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep584020_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep584040_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep585040_firmware | < 3.20 | 3.20 |
| schneider-electric | modicon_m580_bmep586040_firmware | < 3.20 | 3.20 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
dogtag-pki vulnerabilities
osv·2024-12-10·CVSS 7.5
CVE-2017-7537 dogtag-pki vulnerabilities
dogtag-pki vulnerabilities
Christina Fu discovered that Dogtag PKI accidentally enabled a mock
authentication plugin by default. An attacker could potentially use
this flaw to bypass the regular authentication process and trick the
CA server into issuing certificates. This issue only affected Ubuntu
16.04 LTS. (CVE-2017-7537)
It was discovered that Dogtag PKI did not properly sanitize user
input. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 22.04 LTS. (CVE-2020-25715)
It was discovered that the XML parser did not properly handle entity
expansion. A remote attacker could potentially retrieve the content of
arbitrary files by sending specially crafted HTTP requests. This issue
only affected Ubun
GHSA
GHSA-9vj3-52fm-gw3x: A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum
ghsa_unreviewed·2022-05-24
CVE-2020-7537 [HIGH] CWE-754 GHSA-9vj3-52fm-gw3x: A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-11
Published