Description
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.
Scores
CVSS v3
6.5
EPSS
0.0012
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-552
Status
published
Products (3)
schneider-electric/bmxnoe0100_firmware
schneider-electric/bmxnoe0110_firmware
schneider-electric/modicon_m340_firmware
Published
Jun 12, 2024
Tracked Since
Feb 18, 2026