CVE-2024-12142

HIGH

Schneider Electric Modicon M340 & BMXNOE0100/BMXNOE0110/BMXNOR0200H - DoS & Info Disclosure via Web Manipulation

Title source: llm
STIX 2.1

Description

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure of restricted web page, modification of web page and denial of service when specific web pages are modified and restricted functions are invoked.

Scores

CVSS v3 8.6
EPSS 0.0033
EPSS Percentile 25.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (4)
Schneider Electric/BMXNOE0100 All versions
Schneider Electric/BMXNOE0110 All Versions
Schneider Electric/BMXNOR0200H Versions prior to SV1.70IR26
Schneider Electric/Modicon M340 processors (part numbers BMXP34*) All versions
Published Jan 17, 2025
Tracked Since Feb 18, 2026