VYPR

Bmxnor0200

by Schneider Electric

CVEs (4)

  • CVE-2018-7811CriNov 30, 2018
    risk 0.64cvss 9.8epss 0.04

    An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server

  • CVE-2018-7812HigDec 17, 2018
    risk 0.49cvss 7.5epss 0.04

    An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the…

  • CVE-2018-7830HigNov 30, 2018
    risk 0.49cvss 7.5epss 0.02

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP…

  • CVE-2015-7937Dec 21, 2015
    risk 0.01cvss epss 0.07

    Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.