CVE-2020-7541: Medium severity schneider electric modicon m340 bmxp341000 firmware vulnerability
A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7541?
CVE-2020-7541 is a Direct Request (Forced Browsing) vulnerability in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium.
Which software versions are affected by CVE-2020-7541?
The affected software versions include Schneider-electric Bmxp341000 Firmware up to version 3.30, Schneider-electric Bmxp342000 Firmware up to version 3.30, Schneider-electric Bmxp3420102 Firmware up to version 3.30, Schneider-electric Bmxp3420102cl Firmware up to version 3.30, Schneider-electric Bmxp342020 Firmware up to version 3.30, Schneider-electric Bmxp3420302 Firmware up to version 3.30, Schneider-electric Bmxp3420302cl Firmware up to version 3.30, Schneider-electric Bmxnoe0100 Firmware up to version 3.3, Schneider-electric Bmxnoe0110 Firmware up to version 6.5, and Schneider-electric Bmxnoc0401 Firmware up to version 2.10.
What is the severity of CVE-2020-7541?
The severity of CVE-2020-7541 is medium with a CVSS score of 5.3.
How can I fix CVE-2020-7541?
To fix CVE-2020-7541, update the affected software versions to the latest available versions.
Where can I find more information about CVE-2020-7541?
You can find more information about CVE-2020-7541 at the following link: [SEVD-2020-343-03](https://www.se.com/ww/en/download/document/SEVD-2020-343-03/)