CVE-2020-7563
Last modified
CVE-2020-7563 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon Tsxety4103 Firmware | All versions |
| Schneider-Electric | Modicon Tsxety5103 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp574634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp575634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp576634 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140noe77101 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140noe77111 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140noc78100 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140cpu65150 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140cpu65150c Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140cpu65160c Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140cpu65160 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx P34-2010 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx P34-2030 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noc 0401 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0100 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0100h Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0110 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Noe 0110h Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmx Nor 0200h Firmware | All versions |
References
- https://www.se.com/ww/en/download/document/SEVD-2020-315-01/Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-01/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7563?
How severe is CVE-2020-7563?
How do I fix CVE-2020-7563?
Are you affected by CVE-2020-7563?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
