Vulnerability Description
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon Tsxety4103 Firmware | All versions |
| Schneider-Electric | Modicon Tsxety4103 | - |
| Schneider-Electric | Modicon Tsxety5103 Firmware | All versions |
| Schneider-Electric | Modicon Tsxety5103 | - |
| Schneider-Electric | Modicon Tsxp574634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp574634 | - |
| Schneider-Electric | Modicon Tsxp575634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp575634 | - |
| Schneider-Electric | Modicon Tsxp576634 Firmware | All versions |
| Schneider-Electric | Modicon Tsxp576634 | - |
| Schneider-Electric | Modicon Quantum 140Noe77101 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Noe77101 | - |
| Schneider-Electric | Modicon Quantum 140Noe77111 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Noe77111 | - |
| Schneider-Electric | Modicon Quantum 140Noc78100 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Noc78100 | - |
| Schneider-Electric | Modicon Quantum 140Cpu65150 Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Cpu65150 | - |
| Schneider-Electric | Modicon Quantum 140Cpu65150C Firmware | All versions |
| Schneider-Electric | Modicon Quantum 140Cpu65150C | - |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2020-315-01/Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-01/Vendor Advisory
FAQ
What is CVE-2020-7563?
CVE-2020-7563 is a vulnerability with a CVSS score of 8.8 (HIGH). A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) ...
How severe is CVE-2020-7563?
CVE-2020-7563 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7563?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon Tsxety4103 Firmware, Schneider-Electric Modicon Tsxety4103, Schneider-Electric Modicon Tsxety5103 Firmware, Schneider-Electric Modicon Tsxety5103, Schneider-Electric Modicon Tsxp574634 Firmware.