CVE-2020-7541

MEDIUMCVSS 5.3/10EPSS 0.87%

Last modified

CVE-2020-7541 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.

Description

A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
0.87%

54.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Schneider-ElectricModicon M340 Bmxp341000 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp342000 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420102 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420102cl Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp342020 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420302 Firmware< 3.30
Schneider-ElectricModicon M340 Bmxp3420302cl Firmware< 3.30
Schneider-ElectricBmxnoe0100 Firmware< 3.3
Schneider-ElectricBmxnoe0110 Firmware< 6.5
Schneider-ElectricBmxnoc0401 Firmware< 2.10
Schneider-ElectricTsxp574634 Firmware< 6.1
Schneider-ElectricTsxp575634 Firmware< 6.1
Schneider-ElectricTsxp576634 Firmware< 6.1
Schneider-ElectricTsxety4103 Firmware< 6.2
Schneider-ElectricTsxety5103 Firmware< 6.4
Schneider-Electric140cpu65150 Firmware< 6.1
Schneider-Electric140noe77111 Firmware< 7.1
Schneider-Electric140noc78100 Firmware< 1.74
Schneider-Electric140noc78000 Firmware< 1.74
Schneider-Electric140noc77101 Firmware< 1.08

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-7541?
A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.
How severe is CVE-2020-7541?
CVE-2020-7541 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.87% probability of exploitation in the next 30 days.
How do I fix CVE-2020-7541?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-7541?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST