CVE-2020-7534
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) (All Versions)
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- schneider-electric/modicon m340 bmxp342020 firmware · schneider-electric/140cpu65 firmware · schneider-electric/tsxp57 firmware · schneider-electric/bmxnoc0401 firmware · schneider-electric/bmxnoe01 firmware · schneider-electric/bmxnor0200h firmware · schneider-electric/140noe77111 firmware · schneider-electric/140noc78000 firmware · schneider-electric/tsxety5103 firmware · schneider-electric/tsxety4103 firmware
- Source
- cybersecurity@se.com
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01Patch, Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.