CVE-2013-0663
Schneider Electric Modicon Quantum, M340, and Premium PLC - Cross-Site Request Forgery
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-0663. PoCs published by t4rkd3vilz.
AI-analyzed exploit summary This is a CSRF PoC exploit targeting Schneider Electric PLCs, allowing an attacker to change the password of the device without user interaction. The exploit uses an HTML form to submit a password change request to the vulnerable endpoint.
Description
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.
Exploits (1)
This is a CSRF PoC exploit targeting Schneider Electric PLCs, allowing an attacker to change the password of the device without user interaction. The exploit uses an HTML form to submit a password change request to the vulnerable endpoint.