CVE-2020-7562
Description
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| schneider-electric | modicon_tsxety4103 | - | |
| schneider-electric | modicon_tsxety5103 | - | |
| schneider-electric | modicon_tsxp574634 | - | |
| schneider-electric | modicon_tsxp575634 | - | |
| schneider-electric | modicon_tsxp576634 | - | |
| schneider-electric | modicon_quantum_140noe77101 | - | |
| schneider-electric | modicon_quantum_140noe77111 | - | |
| schneider-electric | modicon_quantum_140noc78100 | - | |
| schneider-electric | modicon_quantum_140cpu65150 | - | |
| schneider-electric | modicon_quantum_140cpu65150c | - | |
| schneider-electric | modicon_quantum_140cpu65160c | - | |
| schneider-electric | modicon_quantum_140cpu65160 | - | |
| schneider-electric | modicon_m340_bmx_p34-2010 | - | |
| schneider-electric | modicon_m340_bmx_p34-2030 | - | |
| schneider-electric | modicon_m340_bmx_noc_0401 | - | |
| schneider-electric | modicon_m340_bmx_noe_0100 | - | |
| schneider-electric | modicon_m340_bmx_noe_0100h | - | |
| schneider-electric | modicon_m340_bmx_noe_0110 | - | |
| schneider-electric | modicon_m340_bmx_noe_0110h | - | |
| schneider-electric | modicon_m340_bmx_nor_0200h | - | |
References
CWEs
CWE-125
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.