ID

VAR-202012-1391


CVE

CVE-2020-7540


TITLE

plural  Schneider Electric  Vulnerability in lack of authentication for critical features in the product

Trust: 0.8

sources: JVNDB: JVNDB-2020-014331

DESCRIPTION

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause unauthenticated command execution in the controller when sending special HTTP requests. plural Schneider Electric The product is vulnerable to a lack of authentication for critical features.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state

Trust: 1.71

sources: NVD: CVE-2020-7540 // JVNDB: JVNDB-2020-014331 // VULMON: CVE-2020-7540

AFFECTED PRODUCTS

vendor:schneider electricmodel:140noe77111scope:ltversion:7.1

Trust: 1.0

vendor:schneider electricmodel:140cpu65150scope:ltversion:6.1

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp3420102scope:ltversion:3.30

Trust: 1.0

vendor:schneider electricmodel:140noc77101scope:ltversion:1.08

Trust: 1.0

vendor:schneider electricmodel:bmxnoe0110scope:ltversion:6.5

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp3420302scope:ltversion:3.30

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342020scope:ltversion:3.30

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp341000scope:ltversion:3.30

Trust: 1.0

vendor:schneider electricmodel:tsxp575634scope:ltversion:6.1

Trust: 1.0

vendor:schneider electricmodel:140noe77101scope:ltversion:7.1

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp342000scope:ltversion:3.30

Trust: 1.0

vendor:schneider electricmodel:140noc78000scope:ltversion:1.74

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp3420102clscope:ltversion:3.30

Trust: 1.0

vendor:schneider electricmodel:bmxnoe0100scope:ltversion:3.3

Trust: 1.0

vendor:schneider electricmodel:tsxety5103scope:ltversion:6.4

Trust: 1.0

vendor:schneider electricmodel:140noc78100scope:ltversion:1.74

Trust: 1.0

vendor:schneider electricmodel:modicon m340 bmxp3420302clscope:ltversion:3.30

Trust: 1.0

vendor:schneider electricmodel:tsxety4103scope:ltversion:6.2

Trust: 1.0

vendor:schneider electricmodel:tsxp576634scope:ltversion:6.1

Trust: 1.0

vendor:schneider electricmodel:bmxnoc0401scope:ltversion:2.10

Trust: 1.0

vendor:schneider electricmodel:bmxnor200hscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp574634scope:ltversion:6.1

Trust: 1.0

vendor:schneider electricmodel:140cpu65160scope:ltversion:6.1

Trust: 1.0

vendor:schneider electricmodel:140noe 77101scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxnoe0110scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxp3420102scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxp3420302clscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxp3420102clscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxp342020scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxp342000scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxp341000scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxp3420302scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:bmxnoe0100scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-014331 // NVD: CVE-2020-7540

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-7540
value: CRITICAL

Trust: 1.0

NVD: CVE-2020-7540
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202012-938
value: CRITICAL

Trust: 0.6

VULMON: CVE-2020-7540
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2020-7540
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2020-7540
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2020-7540
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2020-7540 // JVNDB: JVNDB-2020-014331 // CNNVD: CNNVD-202012-938 // NVD: CVE-2020-7540

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.0

problemtype:Lack of authentication for important features (CWE-306) [ Other ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-014331 // NVD: CVE-2020-7540

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202012-938

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-202012-938

PATCH

title:SEVD-2020-343-04url:https://www.se.com/ww/en/download/document/SEVD-2020-343-04/

Trust: 0.8

sources: JVNDB: JVNDB-2020-014331

EXTERNAL IDS

db:NVDid:CVE-2020-7540

Trust: 2.5

db:SCHNEIDERid:SEVD-2020-343-04

Trust: 1.7

db:JVNDBid:JVNDB-2020-014331

Trust: 0.8

db:CNNVDid:CNNVD-202012-938

Trust: 0.6

db:VULMONid:CVE-2020-7540

Trust: 0.1

sources: VULMON: CVE-2020-7540 // JVNDB: JVNDB-2020-014331 // CNNVD: CNNVD-202012-938 // NVD: CVE-2020-7540

REFERENCES

url:https://www.se.com/ww/en/download/document/sevd-2020-343-04/

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-7540

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/306.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2020-7540 // JVNDB: JVNDB-2020-014331 // CNNVD: CNNVD-202012-938 // NVD: CVE-2020-7540

SOURCES

db:VULMONid:CVE-2020-7540
db:JVNDBid:JVNDB-2020-014331
db:CNNVDid:CNNVD-202012-938
db:NVDid:CVE-2020-7540

LAST UPDATE DATE

2024-11-23T21:58:51.328000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2020-7540date:2020-12-14T00:00:00
db:JVNDBid:JVNDB-2020-014331date:2021-08-13T08:51:00
db:CNNVDid:CNNVD-202012-938date:2020-12-16T00:00:00
db:NVDid:CVE-2020-7540date:2024-11-21T05:37:20.573

SOURCES RELEASE DATE

db:VULMONid:CVE-2020-7540date:2020-12-11T00:00:00
db:JVNDBid:JVNDB-2020-014331date:2021-08-13T00:00:00
db:CNNVDid:CNNVD-202012-938date:2020-12-11T00:00:00
db:NVDid:CVE-2020-7540date:2020-12-11T01:15:12.377