CVE-2013-0664
Schneider Electric Modicon Quantum, M340, and Premium - Authenticated Remote Code Execution via SOAP Modbus Messages
Title source: llmDescription
The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www.schneider-electric.com/download/ww/en/details/35081317-Vulnerability-Disclosure-for-Quantum-Premium-and-M340/
Vendor Advisory x_refsource_confirm
http://www.schneider-electric.com/download/ww/en/file/36555639-SEVD-2013-023-01.pdf/?fileName=SEVD-2013-023-01.pdf&reference=SEVD-2013-023-01&docType=Technical-paper
US Government Resource x_refsource_misc
http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdf
Scores
EPSS
0.0116
EPSS Percentile
78.8%
Details
Status
published
Products (4)
schneider-electric/modicon_m340
bmxnoe0110x
schneider-electric/modicon_premium
tsxety5103
schneider-electric/modicon_quantum_plc
140noe77111
schneider-electric/modicon_quantum_plc
140nwm10000
Published
Apr 04, 2013
Tracked Since
Feb 18, 2026