QID 591029
Date Published: 2022-09-05
QID 591029: Schneider Electric Modicon PLC Ethernet Communication Modules Vulnerability (SEVD-2014-260-01)
AFFECTED PRODUCTS
The following part numbers are affected:
140CPU65150,140CPU65160,140CPU65260,140NOC77100,140NOC78000,140NOC78100,140NOE77100,140NOE77101,140NOE77101C,140NOE77110,140NOE77111,140NOE77111C,140NWM10000,170ENT11001,170ENT11002,170ENT11002C,171CCC96020,171CCC96020C,171CCC96030,171CCC96030C,171CCC98020,171CCC98030,BMXNOC0401,BMXNOC0402,BMXNOE0100,BMXNOE0110,BMXNOE0110H,BMXNOR0200H,BMXP342020,BMXP342020H,BMXP342030,BMXP3420302,BMXP3420302H,BMXP342030H,BMXPRMxxxx,STBNIC2212,STBNIP2212,TSXETC0101,TSXETC100,TSXETY110WS,TSXETY110WSC,TSXETY4103,TSXETY4103C,TSXETY5103,TSXETY5103C,TSXETZ410,TSXETZ510,TSXNTP100,TSXP572623M,TSXP572623MC,TSXP572823M,TSXP572823MC,TSXP573623AM,TSXP573623M,TSXP573623MC,TSXP574634M,TSXP574823AM,TSXP574823M,TSXP574823MC,TSXP575634M,TSXP576634M,TSXWMY100,TSXWMY100C,TSXP571634M,TSXP572634M,TSXP573634M
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
This vulnerability allows an attacker to bypass the basic authentication on the web server. Using directory traversals an attacker can bypass the basic authentication mechanism in the web server and gain unauthorized access to protected resources. This vulnerability would require network access to the target device through TCP/IP and particularly HTTP
Customers are advised to refer to CERT MITIGATIONS section SEVD-2014-260-01 for affected packages and patching details.
- SEVD-2014-260-01 -
www.se.com/in/en/download/document/SEVD-2014-260-01/
CVEs related to QID 591029
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2014-260-01 |
|