CVE-2020-7534
Summary
| CVE | CVE-2020-7534 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-04 23:15:00 UTC |
| Updated | 2022-02-10 06:45:00 UTC |
| Description | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) (All Versions) |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Schneider-electric | 140cpu65 | - | All | All | All |
| Operating System | Schneider-electric | 140cpu65 Firmware | All | All | All | All |
| Hardware | Schneider-electric | 140noc78000 | - | All | All | All |
| Operating System | Schneider-electric | 140noc78000 Firmware | All | All | All | All |
| Hardware | Schneider-electric | 140noe77111 | - | All | All | All |
| Operating System | Schneider-electric | 140noe77111 Firmware | All | All | All | All |
| Hardware | Schneider-electric | Bmxnoc0401 | - | All | All | All |
| Operating System | Schneider-electric | Bmxnoc0401 Firmware | All | All | All | All |
| Hardware | Schneider-electric | Bmxnoe01 | - | All | All | All |
| Operating System | Schneider-electric | Bmxnoe01 Firmware | All | All | All | All |
| Hardware | Schneider-electric | Bmxnor0200h | - | All | All | All |
| Operating System | Schneider-electric | Bmxnor0200h Firmware | All | All | All | All |
| Hardware | Schneider-electric | Bmxp342020 | - | All | All | All |
| Operating System | Schneider-electric | Bmxp342020 Firmware | All | All | All | All |
| Hardware | Schneider-electric | Tsxety4103 | - | All | All | All |
| Operating System | Schneider-electric | Tsxety4103 Firmware | All | All | All | All |
| Hardware | Schneider-electric | Tsxety5103 | - | All | All | All |
| Operating System | Schneider-electric | Tsxety5103 Firmware | All | All | All | All |
| Hardware | Schneider-electric | Tsxp57 | - | All | All | All |
| Operating System | Schneider-electric | Tsxp57 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| download.schneider-electric.com/files | MISC | download.schneider-electric.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590823 Schneider Electric Ethernet and Web server on Modicon M340 controller and Communication Modules Multiple Vulnerabilities (SEVD-2022-011-01)