Vulnerability Description
CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M340 Bmxp3420302 Firmware | < 3.20 |
| Schneider-Electric | Modicon M340 Bmxp3420302 | - |
| Schneider-Electric | Modicon M340 Bmxp342000 Firmware | < 3.20 |
| Schneider-Electric | Modicon M340 Bmxp342000 | - |
| Schneider-Electric | Modicon M340 Bmxp341000 Firmware | < 3.20 |
| Schneider-Electric | Modicon M340 Bmxp341000 | - |
| Schneider-Electric | Modicon M340 Bmxp3420102 Firmware | < 3.20 |
| Schneider-Electric | Modicon M340 Bmxp3420102 | - |
| Schneider-Electric | Bmxnoe0100 Firmware | < 3.3 |
| Schneider-Electric | Bmxnoe0100 | - |
| Schneider-Electric | Bmxnoe0110 Firmware | < 6.5 |
| Schneider-Electric | Bmxnoe0110 | - |
| Schneider-Electric | Bmxnoc0401 Firmware | < 2.10 |
| Schneider-Electric | Bmxnoc0401 | - |
| Schneider-Electric | Tsxp574634 Firmware | < 6.1 |
| Schneider-Electric | Tsxp574634 | - |
| Schneider-Electric | Tsxp575634 Firmware | < 6.1 |
| Schneider-Electric | Tsxp575634 | - |
| Schneider-Electric | Tsxp576634 Firmware | < 6.1 |
| Schneider-Electric | Tsxp576634 | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_File_Name=SEVD-2020-287-01_Modic
- https://www.se.com/ww/en/download/document/SEVD-2020-287-01/Vendor Advisory
FAQ
What is CVE-2020-7533?
CVE-2020-7533 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.
How severe is CVE-2020-7533?
CVE-2020-7533 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-7533?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M340 Bmxp3420302 Firmware, Schneider-Electric Modicon M340 Bmxp3420302, Schneider-Electric Modicon M340 Bmxp342000 Firmware, Schneider-Electric Modicon M340 Bmxp342000, Schneider-Electric Modicon M340 Bmxp341000 Firmware.