CVE-2018-7760

CRITICAL

Schneider Electric Modicon M340 Premium Quantum PLC BMXNOR0200 - Authorization Bypass via CGI Function Requests

Title source: llm
STIX 2.1

Description

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0014
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (50)
schneider-electric/140cpu31110_firmware
schneider-electric/140cpu31110c_firmware
schneider-electric/140cpu43412u_firmware
schneider-electric/140cpu43412uc_firmware
schneider-electric/140cpu65150_firmware
schneider-electric/140cpu65150c_firmware
schneider-electric/140cpu65160_firmware
schneider-electric/140cpu65160c_firmware
schneider-electric/140cpu65160s_firmware
schneider-electric/140cpu65260_firmware
... and 40 more
Published Apr 18, 2018
Tracked Since Feb 18, 2026