Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request.
2018-11-30T19:29:00.547
2024-11-21T04:12:50.383
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | schneider-electric | modicom_m340_firmware | * | Yes |
| Hardware | schneider-electric | modicom_m340 | - | No |
| Operating System | schneider-electric | modicom_premium_firmware | * | Yes |
| Hardware | schneider-electric | modicom_premium | * | No |
| Operating System | schneider-electric | modicom_quantum_firmware | * | Yes |
| Hardware | schneider-electric | modicom_quantum | * | No |
| Operating System | schneider-electric | modicom_bmxnor0200h_firmware | * | Yes |
| Hardware | schneider-electric | modicom_bmxnor0200h | - | No |