First published: Fri Oct 03 2014(Updated: )
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
schneider-electric stbnic2212 | ||
Schneider Electric STBNIC2212 Firmware | ||
Schneider Electric STBNIP2212 Firmware | ||
Schneider Electric STBNIP2212 Firmware | ||
Schneider Electric TSXETC0101 Firmware | ||
Schneider Electric TSXETC0101 Firmware | ||
Schneider Electric TSXETC100 | ||
Schneider Electric TSXETC100 | ||
Schneider Electric TSXP573623MC Firmware | ||
Schneider Electric TSXP573623MC Firmware | ||
Schneider Electric TSXETY110WS | ||
Schneider Electric TSXETY110WS | ||
schneider-electric tsxp574634m firmware | ||
Schneider Electric TSXP574634M | ||
Schneider Electric TSXETY110WSC Firmware | ||
Schneider Electric TSXETY110WSC Firmware | ||
Schneider Electric TSXP574823AM Firmware | ||
Schneider Electric TSXP574823AM Firmware | ||
Schneider Electric TSXETY4103 Firmware | ||
Schneider Electric TSXETY4103C | ||
Schneider Electric TSXP574823M | ||
schneider-electric tsxp574823m firmware | ||
Schneider Electric TSXETY4103 Firmware | ||
Schneider Electric TSXETY4103 Firmware | ||
schneider-electric tsxp574823mc | ||
schneider-electric tsxp574823mc firmware | ||
schneider-electric tsxety5103c firmware | ||
schneider-electric TSXETY5103 firmware | ||
schneider-electric tsxp575634m firmware | ||
Schneider Electric TSXP575634M | ||
Schneider Electric TSXETY5103C | ||
schneider-electric tsxety5103c firmware | ||
schneider-electric tsxp576634mc firmware | ||
schneider-electric tsxp576634m firmware | ||
Schneider Electric TSXETZ410 | ||
Schneider Electric TSXETZ410 | ||
schneider-electric tsxwmy100 firmware | ||
Schneider Electric TSXWMY100 | ||
Schneider Electric TSXETZ510 Firmware | ||
Schneider Electric TSXETZ510 Firmware | ||
Schneider Electric TSXWMY100C Firmware | ||
Schneider Electric TSXWMY100C Firmware | ||
Schneider Electric TSX NTP 100 Firmware | ||
Schneider Electric TSX NTP 100 Firmware | ||
Schneider Electric Modicon M580 Firmware | ||
Schneider Electric Modicon M580 Firmware | ||
schneider-electric Modicon M340 BMXNOE0100 | ||
schneider-electric Modicon M340 BMXNOE0100 firmware | ||
Schneider Electric Modicon M340 BMXNOE0110 Firmware | ||
Schneider Electric Modicon M340 BMXNOE0110 Firmware | ||
Schneider Electric Modicon M340 BMX NOE 0110H | ||
schneider-electric Modicon M340 | ||
Schneider Electric Modicon M340 BMX NOR 0200H firmware | ||
Schneider Electric Modicon M340 BMXNOR0200H | ||
Schneider Electric Modicon M340 BMXP342020 Firmware | ||
Schneider Electric Modicon M340 BMXP342020 | ||
Schneider Electric Modicon M340 BMXP342020H Firmware | ||
Schneider Electric Modicon M340 BMXP342020H | ||
Schneider Electric Modicon M340 BMXP342030 Firmware | ||
Schneider Electric Modicon M340 BMXP342030H | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
Schneider Electric Modicon M340 BMXP3420302H Firmware | ||
Schneider Electric Modicon M340 BMXP3420302H Firmware | ||
Schneider Electric Modicon M340 BMXP342030H Firmware | ||
Schneider Electric Modicon M340 BMXP342030H | ||
Schneider Electric Modicon M340 BMXNOC0401 | ||
Schneider Electric Modicon M340 BMXNOC0401 | ||
schneider-electric 171ccc96020c firmware | ||
schneider-electric 171ccc98020 firmware | ||
Schneider Electric 171CCC96020 | ||
schneider-electric 171ccc96020c firmware | ||
Schneider Electric 171CCC96030C Firmware | ||
Schneider Electric 171CCC98030 | ||
schneider-electric 171ccc96030c | ||
Schneider Electric 171CCC96030C Firmware | ||
schneider-electric 171ccc98020 firmware | ||
schneider-electric 171ccc98020 | ||
Schneider Electric 171CCC98030 | ||
Schneider Electric 171CCC98030 | ||
schneider-electric tsxp571634mc firmware | ||
Schneider Electric TSXP571634M Firmware | ||
Schneider Electric TSXP572634M Firmware | ||
Schneider Electric TSXP572634M | ||
Schneider Electric TSXP573634M Firmware | ||
Schneider Electric TSXP573634M |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0754 is categorized as a medium severity vulnerability.
To fix CVE-2014-0754, update the affected firmware versions of Schneider Electric Modicon PLC Ethernet modules to the latest version available.
CVE-2014-0754 is a directory traversal vulnerability that enables unauthorized file system access.
CVE-2014-0754 affects several Schneider Electric Modicon PLC Ethernet modules, including the 140CPU65x and others listed in the CVE record.
Yes, CVE-2014-0754 can potentially be exploited remotely if appropriate network security measures are not in place.