CVE-2013-2763
Last modified
CVE-2013-2763 is a vulnerability of currently unknown severity. The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M340 Bmx Noc 0401 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0100 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0100h Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0110 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0110h Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Nor 0200h Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx P34-2010 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx P34-2030 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp341000 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342010 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342020 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342030 Firmware | All versions |
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdfBroken Link, Third Party Advisory, US Government Resource
- http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdfBroken Link, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2763?
How severe is CVE-2013-2763?
How do I fix CVE-2013-2763?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2756Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatfor…
- CVE-2013-2757Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x befo…
- CVE-2013-2758Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatfor…
- CVE-2013-2760Buffer overflow in Groovy Media Player 3.2.0 allows remote a…
- CVE-2013-2761The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC mo…
- CVE-2013-2762The Schneider Electric Magelis XBT HMI controller has a defa…
- CVE-2013-2764Secure Entry Server before 4.7.0 contains a URI Redirection …6.1
- CVE-2013-2765The ModSecurity module before 2.7.4 for the Apache HTTP Serv…
- CVE-2013-2766Cross-site scripting (XSS) vulnerability in Splunk Web in Sp…
- CVE-2013-2767Unspecified vulnerability in Citrix NetScaler Access Gateway…
- CVE-2013-2770The installation functionality in the Novell Kanaka componen…
- CVE-2013-2773Nitro PDF 8.5.0.26: A specially crafted DLL file can facilit…7.8
Are you affected by CVE-2013-2763?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
