Vulnerability Description
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon Tsxety4103 Firmware | All versions |
| Schneider-Electric | Modicon Tsxety4103 | - |
| Schneider-Electric | Modicon Tsxety5103 Firmware | All versions |
| Schneider-Electric | Modicon Tsxety5103 | - |
| Schneider-Electric | Modicon Tsxp574634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp574634 | - |
| Schneider-Electric | Modicon Tsxp575634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp575634 | - |
| Schneider-Electric | Modicon Tsxp576634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp576634 | - |
| Schneider-Electric | Modicon Quantum 140Noe77101 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Noe77101 | - |
| Schneider-Electric | Modicon Quantum 140Noe77111 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Noe77111 | - |
| Schneider-Electric | Modicon Quantum 140Noc78100 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Noc78100 | - |
| Schneider-Electric | Modicon Quantum 140Cpu65150 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Cpu65150 | - |
| Schneider-Electric | Modicon Quantum 140Cpu65150C Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Cpu65150C | - |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2020-315-01/Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-01/Vendor Advisory
FAQ
What is CVE-2020-7562?
CVE-2020-7562 is a vulnerability with a CVSS score of 8.1 (HIGH). A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) w...
How severe is CVE-2020-7562?
CVE-2020-7562 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7562?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon Tsxety4103 Firmware, Schneider-Electric Modicon Tsxety4103, Schneider-Electric Modicon Tsxety5103 Firmware, Schneider-Electric Modicon Tsxety5103, Schneider-Electric Modicon Tsxp574634 Firmware.