Description
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
References (2)
Core 2
Core References
Not Applicable, Vendor Advisory x_refsource_confirm
https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-281-02/
Vendor Advisory
https://www.se.com/ww/en/download/document/SEVD-2019-316-02%20/
Scores
CVSS v3
7.5
EPSS
0.0035
EPSS Percentile
57.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (10)
schneider-electric/140_cpu6x_firmware
schneider-electric/140_noc_77101_firmware
schneider-electric/140_noc_78x00_firmware
schneider-electric/140_noe_771x1_firmware
schneider-electric/bmx_noc_0401_firmware
schneider-electric/bmx_noe_0100_firmware
schneider-electric/bmx_noe_0110_firmware
schneider-electric/bmx_p34x_firmware
schneider-electric/tsx_ety_x103_firmware
schneider-electric/tsx_p57x_firmware
Published
Nov 20, 2019
Tracked Since
Feb 18, 2026