CVE-2020-7533

CRITICAL

Schneider Electric Modicon M340 RCE via Crafted HTTP Requests

Title source: llm
STIX 2.1

Description

CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.

Scores

CVSS v3 9.8
EPSS 0.0023
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (16)
schneider-electric/140cpu65260_firmware < 6.1
schneider-electric/140noc77101_firmware < 1.08
schneider-electric/140noc78000_firmware < 1.74
schneider-electric/140noe77111_firmware < 7.1
schneider-electric/bmxnoc0401_firmware < 2.10
schneider-electric/bmxnoe0100_firmware < 3.3
schneider-electric/bmxnoe0110_firmware < 6.5
schneider-electric/modicon_m340_bmxp341000_firmware < 3.20
schneider-electric/modicon_m340_bmxp342000_firmware < 3.20
schneider-electric/modicon_m340_bmxp3420102_firmware < 3.20
... and 6 more
Published Dec 01, 2020
Tracked Since Feb 18, 2026