ID

VAR-201410-1134


CVE

CVE-2014-0754


TITLE

Schneider Electric Modicon PLC Ethernet Module SchneiderWEB Vulnerable to directory traversal

Trust: 0.8

sources: JVNDB: JVNDB-2014-004531

DESCRIPTION

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request. Schneider Electric provides products and services in the areas of energy and infrastructure, industry, data centers and networks, buildings and residential. Exploiting this issue can allow an attacker to gain access to arbitrary files. Information harvested may aid in launching further attacks. Schneider Electric Modicon PLC Ethernet is an Ethernet programmable controller produced by French Schneider Electric (Schneider Electric). The following versions are affected: Schneider Electric Modicon PLC Ethernet modules 140CPU65x Version, 140NOC78x Version, 140NOE77x Version, BMXNOC0401 Version, BMXNOC0402 Version, BMXNOE0100 Version, BMXNOE0110x Version, TSXETC101 Version, TSXETC0101 Version, TSXETY4103x Version, TSXETY5103x Version, TSXP57x Version, TSXP57x Version

Trust: 2.7

sources: NVD: CVE-2014-0754 // JVNDB: JVNDB-2014-004531 // CNVD: CNVD-2014-06695 // BID: 70193 // IVD: cce5fe38-2351-11e6-abef-000c29c66e3d // VULHUB: VHN-68247

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: cce5fe38-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06695

AFFECTED PRODUCTS

vendor:schneider electricmodel:modicon m340 bmxp342030hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp575634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp574823amscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxnoe0110hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxety4103cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxntp100scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp574823mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxnoe0110scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxnoc0401scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxety5103cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp573634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:171ccc96020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342020hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp571634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:stbnic2212scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp3420302hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:171ccc98020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxwmy100scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxetc0101scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:stbnip2212scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:171ccc96020cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp574634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxetz510scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342030scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp3420302scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxetz410scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342020scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxety110wscscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp573623mcscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxety110wsscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxety4103scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxnoe0100scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:171ccc98030scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxety5103scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxwmy100cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m580 bmxnoc0402scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxetc100scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:171ccc96030cscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp572634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxnor0200hscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp576634mscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:tsxp574823mcscope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:171ccc96030scope:eqversion: -

Trust: 1.0

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:140cpu65x exec 5.5

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:140noc78x exec 1.62

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:140noe77x exec 6.2

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:bmxnoc0401 2.05

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:bmxnoe0100 2.9

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:bmxnoe0110x exec 6.0

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:tsxetc101 exec 2.04

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:tsxety4103x exec 5.7

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:tsxety5103x exec 5.9

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:tsxp57x ethernet copro exec 5.5

Trust: 0.8

vendor:schneider electricmodel:modicon plc ethernet communication modulescope:ltversion:tsxp57x etyport exec 5.7

Trust: 0.8

vendor:schneidermodel:electric modicon plc ethernet modulescope: - version: -

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:bmxp3420302h

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:bmxp342030h

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:tsxp573634m

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:140cpu65160

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:tsxp572623mc

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:tsxp572623m

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:140cpu65150

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:171ccc96020

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:140cpu65260

Trust: 0.6

vendor:schneider electricmodel:modicon plc ethernet modulescope:eqversion:171ccc96020c

Trust: 0.6

vendor:schneider electricmodel:tsxwmy100scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxwmy10scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp576634scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp575634scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp574823mscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp574823ascope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp574823scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp574634scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp573634scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp573623mscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp573623ascope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp573623scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp572823mscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp572823scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp572634scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp572623mcscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp572623mscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxp571634mscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxntp100scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxetz510scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxetz410scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxety5103cscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxety5103scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxety4103cscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxety4103scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxety110wscscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxety110wsscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxetc100scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:tsxetc0101scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxprmxxxxscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxp342030hscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxp3420302hscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxp342030scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxp342020hscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxp342020scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxnor0200hscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxnoe0110hscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxnoe0110scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxnoe0100scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxnoc0402scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmxnoc0401scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:bmx noescope:eqversion:01100

Trust: 0.3

vendor:schneider electricmodel:171ccc98030scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:171ccc98020scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:171ccc96030cscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:171ccc96030scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:171ccc96020cscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:171ccc96020scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:170ent11002scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:170ent11001scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140nwm10000scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noe77111cscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noe77111scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noe77110scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noe77101cscope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noe77101scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noe77100scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noc78100scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noc78000scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140noc77100scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140cpu65260scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140cpu65160scope:eqversion:0

Trust: 0.3

vendor:schneider electricmodel:140cpu65150scope:eqversion:0

Trust: 0.3

vendor:modicon plc ethernet modulemodel:bmxnor0200hscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140cpu65150scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140cpu65160scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140cpu65260scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noc77100scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noc78000scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noe77100scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noe77101scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noe77101cscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noe77110scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noe77111scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140noe77111cscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:140nwm10000scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:170ent11001scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:170ent11002scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:170ent11002cscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:171ccc96020scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:171ccc96020cscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:171ccc96030scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:171ccc96030cscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:171ccc98020scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:171ccc98030scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxnoc0401scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxnoc0402scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxnoe0100scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxnoe0110scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxnoe0110hscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxp342020scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxp342020hscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxp342030scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxp342030hscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxp3420302scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxp3420302hscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:bmxprmxxxxscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:stbnic2212scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:stbnip2212scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxetc100scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxetc0101scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxety110wsscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxety110wscscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxety4103scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxety4103cscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxety5103scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxety5103cscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxetz410scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxetz510scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxntp100scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp571634mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp572623mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp572623mcscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp572823mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp572823mcscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp573623amscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp573623mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp573623mcscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp573634mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp574634mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp574823amscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp574823mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp574823mcscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp575634mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxp576634mscope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxwmy100scope: - version: -

Trust: 0.2

vendor:modicon plc ethernet modulemodel:tsxwmy100cscope: - version: -

Trust: 0.2

sources: IVD: cce5fe38-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06695 // BID: 70193 // JVNDB: JVNDB-2014-004531 // CNNVD: CNNVD-201410-075 // NVD: CVE-2014-0754

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0754
value: HIGH

Trust: 1.0

NVD: CVE-2014-0754
value: HIGH

Trust: 0.8

CNVD: CNVD-2014-06695
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201410-075
value: CRITICAL

Trust: 0.6

IVD: cce5fe38-2351-11e6-abef-000c29c66e3d
value: CRITICAL

Trust: 0.2

VULHUB: VHN-68247
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-0754
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-06695
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: cce5fe38-2351-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-68247
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: IVD: cce5fe38-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06695 // VULHUB: VHN-68247 // JVNDB: JVNDB-2014-004531 // CNNVD: CNNVD-201410-075 // NVD: CVE-2014-0754

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.9

sources: VULHUB: VHN-68247 // JVNDB: JVNDB-2014-004531 // NVD: CVE-2014-0754

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-075

TYPE

Path traversal

Trust: 0.8

sources: IVD: cce5fe38-2351-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201410-075

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004531

PATCH

title:Modicon PLC Ethernet Communication Modulesurl:http://download.schneider-electric.com/files?p_Reference=SEVD-2014-260-01&p_EnDocType=Software%20-%20Updates&p_File_Id=608959359&p_File_Name=SEVD-2014-260-01.pdf

Trust: 0.8

title:Patches for multiple Schneider Electric product catalog traversal vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/50841

Trust: 0.6

title:BMXNOE0100+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54170

Trust: 0.6

title:BMXNOE0110+Web+and+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54171

Trust: 0.6

title:140NOE77101+Exec+For+Unity+Usersurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54184

Trust: 0.6

title:140NOE77101+Exec+For+Non+Unity+Usersurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54183

Trust: 0.6

title:140NOE77111+Exec+For+Unity+and+Non+Unity+Usersurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54185

Trust: 0.6

title:140CPU65260+Quantum+Copro+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54180

Trust: 0.6

title:140CPU65160+Quantum+Copro+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54179

Trust: 0.6

title:140CPU65150+Quantum+CoPro+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54178

Trust: 0.6

title:140NOC78000+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54181

Trust: 0.6

title:TSXP575634M+Premium+Copro+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54176

Trust: 0.6

title:TSXP574634M+Premium+Copro+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54175

Trust: 0.6

title:TSXP576634M+Premium+Copro+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54177

Trust: 0.6

title:TSXETC101+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54172

Trust: 0.6

title:140NOC78100+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54182

Trust: 0.6

title:TSXP573634M+ETY+Port+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54188

Trust: 0.6

title:TSXP572634M+ETY+Port+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54187

Trust: 0.6

title:TSXETY5103+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54174

Trust: 0.6

title:TSXP571634M+ETY+Port+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54186

Trust: 0.6

title:TSXETY4103+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54173

Trust: 0.6

title:BMXNOC0401+Execurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=54169

Trust: 0.6

sources: CNVD: CNVD-2014-06695 // JVNDB: JVNDB-2014-004531 // CNNVD: CNNVD-201410-075

EXTERNAL IDS

db:NVDid:CVE-2014-0754

Trust: 3.6

db:ICS CERTid:ICSA-14-273-01

Trust: 3.4

db:BIDid:70193

Trust: 2.6

db:SCHNEIDERid:SEVD-2014-260-01

Trust: 2.0

db:CNNVDid:CNNVD-201410-075

Trust: 0.9

db:CNVDid:CNVD-2014-06695

Trust: 0.8

db:JVNDBid:JVNDB-2014-004531

Trust: 0.8

db:IVDid:CCE5FE38-2351-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:VULHUBid:VHN-68247

Trust: 0.1

sources: IVD: cce5fe38-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-06695 // VULHUB: VHN-68247 // BID: 70193 // JVNDB: JVNDB-2014-004531 // CNNVD: CNNVD-201410-075 // NVD: CVE-2014-0754

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-14-273-01

Trust: 3.4

url:http://www.securityfocus.com/bid/70193

Trust: 1.7

url:http://download.schneider-electric.com/files?p_reference=sevd-2014-260-01&p_endoctype=software%20-%20updates&p_file_id=608959359&p_file_name=sevd-2014-260-01.pdf

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0754

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0754

Trust: 0.8

url:http://www.schneider-electric.com/site/home/index.cfm/ww/?selectcountry=true

Trust: 0.3

url:http://download.schneider-electric.com/files?p_doc_ref=sevd-2014-260-01

Trust: 0.3

url:http://download.schneider-electric.com/files?p_reference=sevd-2014-260-01&p_endoctype=software%20-%20updates&p_file_id=608959359&p_file_name=sevd-2014-260-01.pdf

Trust: 0.1

sources: CNVD: CNVD-2014-06695 // VULHUB: VHN-68247 // BID: 70193 // JVNDB: JVNDB-2014-004531 // CNNVD: CNNVD-201410-075 // NVD: CVE-2014-0754

CREDITS

Billy Rios

Trust: 0.3

sources: BID: 70193

SOURCES

db:IVDid:cce5fe38-2351-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-06695
db:VULHUBid:VHN-68247
db:BIDid:70193
db:JVNDBid:JVNDB-2014-004531
db:CNNVDid:CNNVD-201410-075
db:NVDid:CVE-2014-0754

LAST UPDATE DATE

2024-11-23T22:13:39.284000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-06695date:2014-10-14T00:00:00
db:VULHUBid:VHN-68247date:2016-04-04T00:00:00
db:BIDid:70193date:2014-09-30T00:00:00
db:JVNDBid:JVNDB-2014-004531date:2014-10-07T00:00:00
db:CNNVDid:CNNVD-201410-075date:2022-02-11T00:00:00
db:NVDid:CVE-2014-0754date:2024-11-21T02:02:44.980

SOURCES RELEASE DATE

db:IVDid:cce5fe38-2351-11e6-abef-000c29c66e3ddate:2014-10-14T00:00:00
db:CNVDid:CNVD-2014-06695date:2014-10-14T00:00:00
db:VULHUBid:VHN-68247date:2014-10-03T00:00:00
db:BIDid:70193date:2014-09-30T00:00:00
db:JVNDBid:JVNDB-2014-004531date:2014-10-07T00:00:00
db:CNNVDid:CNNVD-201410-075date:2014-10-13T00:00:00
db:NVDid:CVE-2014-0754date:2014-10-03T18:55:06.017