Vulnerabilities > Schneider Electric > Bmxnoe0100 Firmware

DATE CVE VULNERABILITY TITLE RISK
2020-12-01 CVE-2020-7533 Unspecified vulnerability in Schneider-Electric products
A CWE-255: Credentials Management vulnerability exists in Web Server on Modicon M340, Modicon Quantum and ModiconPremium Legacy offers and their Communication Modules (see security notification for version information) which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.
network
low complexity
schneider-electric
critical
9.8
2019-03-21 CVE-2015-6462 Cross-site Scripting vulnerability in Schneider-Electric products
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.
network
low complexity
schneider-electric CWE-79
5.4
2019-03-21 CVE-2015-6461 Improper Input Validation vulnerability in Schneider-Electric products
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.
network
low complexity
schneider-electric CWE-20
5.4
2017-06-30 CVE-2017-6017 Resource Exhaustion vulnerability in Schneider-Electric products
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H.
network
low complexity
schneider-electric CWE-400
7.5