CVE-2020-7533
Summary
| CVE | CVE-2020-7533 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-01 15:15:00 UTC |
| Updated | 2022-04-25 17:45:00 UTC |
| Description | A CWE-255: Credentials Management vulnerability exists in Web Server on Modicon M340, Modicon Quantum and ModiconPremium Legacy offers and their Communication Modules (see security notification for version information) which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Notification - Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules | Schneider Electric | MISC | www.se.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590775 Schneider Electric Web Server on Modicon M340, Quantum and Premium Legacy offers and their Communication Modules Vulnerability (SEVD-2020-287-01)