Vulnerabilities > Schneider Electric > Modicon M340 Bmxp342020 Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-02-14 CVE-2023-6408 Unspecified vulnerability in Schneider-Electric products
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
network
high complexity
schneider-electric
8.1
2023-02-01 CVE-2021-22786 Unspecified vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol.
network
low complexity
schneider-electric
7.5
2023-01-31 CVE-2022-45789 Unspecified vulnerability in Schneider-Electric products
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-45788 Unspecified vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller.
network
low complexity
schneider-electric
critical
9.8
2022-11-22 CVE-2022-0222 Improper Privilege Management vulnerability in Schneider-Electric products
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP.
network
low complexity
schneider-electric CWE-269
7.5
2022-09-12 CVE-2022-37300 Unspecified vulnerability in Schneider-Electric products
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus.
network
low complexity
schneider-electric
critical
9.8
2022-02-11 CVE-2021-22785 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device.
network
low complexity
schneider-electric CWE-200
7.5
2022-02-11 CVE-2021-22787 Improper Input Validation vulnerability in Schneider-Electric products
A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device.
network
low complexity
schneider-electric CWE-20
7.5
2022-02-11 CVE-2021-22788 Out-of-bounds Write vulnerability in Schneider-Electric products
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device.
network
low complexity
schneider-electric CWE-787
7.5
2022-02-04 CVE-2020-7534 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric products
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in.
network
low complexity
schneider-electric CWE-352
8.8