Schneider-Electric Modicon M340 vulnerabilities
3 known vulnerabilities affecting schneider-electric/modicon_m340.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2013-0664HIGHCVSS 8.5vbmxnoe0110x2013-04-04
CVE-2013-0664 [HIGH] CVE-2013-0664: The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE01
The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests.
nvd
CVE-2013-0663MEDIUMCVSS 6.8PoCvbmxnoc0401vbmxnoe011xx+1 more2013-04-04
CVE-2013-0663 [MEDIUM] CWE-352 CVE-2013-0663: Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NO
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstr
nvd
CVE-2013-2761MEDIUMCVSS 4.0vbmxnoe01xxvbmxp3420xx2013-04-04
CVE-2013-2761 [MEDIUM] CWE-119 CVE-2013-2761: The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users t
The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZilla FTP client.
nvd