Vulnerabilities > Schneider Electric > Modicon M340 Bmxp3420102 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2022-22724 Resource Exhaustion vulnerability in Schneider-Electric products
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC.
network
low complexity
schneider-electric CWE-400
5.0
2020-12-11 CVE-2020-7549 Improper Check for Unusual or Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause denial of HTTP and FTP services when a series of specially crafted requests is sent to the controller over HTTP.
network
low complexity
schneider-electric CWE-754
5.3
2020-12-11 CVE-2020-7541 Forced Browsing vulnerability in Schneider-Electric products
A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.
network
low complexity
schneider-electric CWE-425
5.3