CVE-2020-7540 — Missing Authentication for Critical Function in Modicon M340 Bmxp341000 Firmware
Severity
9.8CRITICALNVD
EPSS
0.3%
top 45.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 24
Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause unauthenticated command execution in the controller when sending special HTTP requests.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages22 packages
🔴Vulnerability Details
2GHSA▶
GHSA-x5fh-cqhm-x62g: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modi↗2022-05-24
CVEList▶
CVE-2020-7540: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modi↗2020-12-11
💬Community
1Bugzilla
▶