CVE-2020-7536

HIGHCVSS 7.5/10EPSS 1.11%

Last modified

CVE-2020-7536 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4 BMXNOE0110 (H) versions prior to V6.6 BMXNOR0200H all versions), that could cause the device to be unreachable when modifying network parameters over SNMP.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.

Description

A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4 BMXNOE0110 (H) versions prior to V6.6 BMXNOR0200H all versions), that could cause the device to be unreachable when modifying network parameters over SNMP.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.11%

61.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Schneider-ElectricModicon M340 Bmxp341000 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp342000 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420102 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420102cl Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp342020 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420302 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420302cl Firmware< 3.30
Schneider-ElectricBmxnoe0100 Firmware< 3.4
Schneider-ElectricBmxnoe0110 Firmware< 6.6
Schneider-ElectricBmxnor0200h FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-7536?
A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4 BMXNOE0110 (H) versions prior to V6.6 BMXNOR0200H all versions), that could cause the device to be unreachable when modifying network parameters over SNMP.
How severe is CVE-2020-7536?
CVE-2020-7536 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.11% probability of exploitation in the next 30 days.
How do I fix CVE-2020-7536?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-7536?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST