An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
2018-12-17T22:29:00.297
2024-11-21T04:12:46.700
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | schneider-electric | modicom_m340_firmware | * | Yes |
| Hardware | schneider-electric | modicom_m340 | - | No |
| Operating System | schneider-electric | modicom_premium_firmware | * | Yes |
| Hardware | schneider-electric | modicom_premium | * | No |
| Operating System | schneider-electric | modicom_quantum_firmware | * | Yes |
| Hardware | schneider-electric | modicom_quantum | * | No |
| Operating System | schneider-electric | modicom_bmxnor0200h_firmware | * | Yes |
| Hardware | schneider-electric | modicom_bmxnor0200h | - | No |