CVE-2020-7533
CRITICALSchneider Electric Modicon M340 RCE via Crafted HTTP Requests
Title source: llmDescription
CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.
References (2)
Core 2
Scores
CVSS v3
9.8
EPSS
0.0023
EPSS Percentile
46.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (16)
schneider-electric/140cpu65260_firmware
< 6.1
schneider-electric/140noc77101_firmware
< 1.08
schneider-electric/140noc78000_firmware
< 1.74
schneider-electric/140noe77111_firmware
< 7.1
schneider-electric/bmxnoc0401_firmware
< 2.10
schneider-electric/bmxnoe0100_firmware
< 3.3
schneider-electric/bmxnoe0110_firmware
< 6.5
schneider-electric/modicon_m340_bmxp341000_firmware
< 3.20
schneider-electric/modicon_m340_bmxp342000_firmware
< 3.20
schneider-electric/modicon_m340_bmxp3420102_firmware
< 3.20
... and 6 more
Published
Dec 01, 2020
Tracked Since
Feb 18, 2026