HIGH · 10.0

CVE-2014-0754

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before...

Vulnerability Description

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Schneider-ElectricStbnic2212 Firmware-
Schneider-ElectricStbnic2212-
Schneider-ElectricStbnip2212 Firmware-
Schneider-ElectricStbnip2212-
Schneider-ElectricTsxetc0101 Firmware-
Schneider-ElectricTsxetc0101-
Schneider-ElectricTsxetc100 Firmware-
Schneider-ElectricTsxetc100-
Schneider-ElectricTsxp573623Mc Firmware-
Schneider-ElectricTsxp573623Mc-
Schneider-ElectricTsxety110Ws Firmware-
Schneider-ElectricTsxety110Ws-
Schneider-ElectricTsxp574634M Firmware-
Schneider-ElectricTsxp574634M-
Schneider-ElectricTsxety110Wsc Firmware-
Schneider-ElectricTsxety110Wsc-
Schneider-ElectricTsxp574823Am Firmware-
Schneider-ElectricTsxp574823Am-
Schneider-ElectricTsxety4103 Firmware-
Schneider-ElectricTsxety4103-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0754?

CVE-2014-0754 is a vulnerability with a CVSS score of 10.0 (HIGH). Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before...

How severe is CVE-2014-0754?

CVE-2014-0754 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0754?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Stbnic2212 Firmware, Schneider-Electric Stbnic2212, Schneider-Electric Stbnip2212 Firmware, Schneider-Electric Stbnip2212, Schneider-Electric Tsxetc0101 Firmware.