CVE-2020-7540Missing Authentication for Critical Function in Modicon M340 Bmxp341000 Firmware

Severity
9.8CRITICALNVD
EPSS
0.3%
top 45.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 24

Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause unauthenticated command execution in the controller when sending special HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-x5fh-cqhm-x62g: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modi2022-05-24
CVEList
CVE-2020-7540: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modi2020-12-11

💬Community

1
Bugzilla
CVE-2020-13790 libjpeg-turbo: heap-based buffer over-read in get_rgb_row() in rdppm.c2020-06-15
CVE-2020-7540 — CRITICAL severity | cvebase