CVE-2013-0664
Summary
| CVE | CVE-2013-0664 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-04-04 11:58:49 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests. |
Risk And Classification
Primary CVSS: v2.0 8.5 from [email protected]
AV:N/AC:M/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Schneider-electric | Modicon M340 | bmxnoe0110x | All | All | All |
| Hardware | Schneider-electric | Modicon Premium | tsxety5103 | All | All | All |
| Hardware | Schneider-electric | Modicon Quantum Plc | 140noe77111 | All | All | All |
| Hardware | Schneider-electric | Modicon Quantum Plc | 140nwm10000 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 - File Not Found | CISA | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | US Government Resource |
| Product Documentation & Software downloads | Schneider Electric | af854a3a-2127-422b-91ae-364da2661108 | www.schneider-electric.com | Vendor Advisory |
| Documents & Downloads | af854a3a-2127-422b-91ae-364da2661108 | www.schneider-electric.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590485 Schneider Electric PLCs (Update B) Multiple Vulnerabilities (ICSA-13-077-01B)