Vulnerabilities > Schneider Electric > Modicon M340 Bmxp3420302 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2022-22724 Resource Exhaustion vulnerability in Schneider-Electric products
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC.
network
low complexity
schneider-electric CWE-400
5.0
2020-12-11 CVE-2020-7549 Improper Check for Unusual or Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause denial of HTTP and FTP services when a series of specially crafted requests is sent to the controller over HTTP.
network
low complexity
schneider-electric CWE-754
5.3
2020-12-11 CVE-2020-7541 Forced Browsing vulnerability in Schneider-Electric products
A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.
network
low complexity
schneider-electric CWE-425
5.3
2019-03-21 CVE-2015-6462 Cross-site Scripting vulnerability in Schneider-Electric products
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.
network
low complexity
schneider-electric CWE-79
5.4
2019-03-21 CVE-2015-6461 Improper Input Validation vulnerability in Schneider-Electric products
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.
network
low complexity
schneider-electric CWE-20
5.4