Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.
2015-12-21T11:59:12.097
2025-04-12T10:46:40.837
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Hardware | schneider-electric | bmxnoc0401 | - | Yes |
Hardware | schneider-electric | bmxnoe0100 | - | Yes |
Hardware | schneider-electric | bmxnoe0100h | - | Yes |
Hardware | schneider-electric | bmxnoe0110 | - | Yes |
Hardware | schneider-electric | bmxnoe0110h | - | Yes |
Hardware | schneider-electric | bmxnor0200 | - | Yes |
Hardware | schneider-electric | bmxnor0200h | - | Yes |
Hardware | schneider-electric | bmxpra0100 | - | Yes |
Hardware | schneider-electric | modicon_m340_bmxp342020 | - | Yes |
Hardware | schneider-electric | modicon_m340_bmxp342020h | - | Yes |
Hardware | schneider-electric | modicon_m340_bmxp342030 | - | Yes |
Hardware | schneider-electric | modicon_m340_bmxp3420302 | - | Yes |
Hardware | schneider-electric | modicon_m340_bmxp3420302h | - | Yes |