Unknown
CVE-2020-7563
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-7563
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- modicon m340 bmx noc 0401 firmware,
- modicon m340 bmx noe 0100 firmware,
- modicon m340 bmx noe 0100h firmware,
- modicon m340 bmx noe 0110 firmware,
- modicon m340 bmx noe 0110h firmware,
- modicon m340 bmx nor 0200h firmware,
- modicon m340 bmx p34-2010 firmware,
- modicon m340 bmx p34-2030 firmware,
- modicon quantum 140cpu65150 firmware,
- modicon quantum 140cpu65150c firmware,
- modicon quantum 140cpu65160 firmware,
- modicon quantum 140cpu65160c firmware,
- modicon quantum 140noc78100 firmware,
- modicon quantum 140noe77101 firmware,
- modicon quantum 140noe77111 firmware,
- modicon tsxety4103 firmware,
- modicon tsxety5103 firmware,
- modicon tsxp574634 firmware,
- modicon tsxp575634 firmware,
- modicon tsxp576634 firmware
Weaknesses
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: