A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FTP service when upgrading the firmware with a version incompatible with the application in the controller using FTP protocol.
2019-10-29T19:15:22.267
2024-11-21T04:47:16.320
Modified
CVSSv3.1: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | modicon_m580_firmware | * | Yes |
Hardware | schneider-electric | modicon_m580 | - | No |
Operating System | schneider-electric | modicon_m340_firmware | * | Yes |
Hardware | schneider-electric | modicon_m340 | - | No |
Operating System | schneider-electric | modicon_bmxcra_firmware | * | Yes |
Hardware | schneider-electric | modicon_bmxcra | - | No |
Operating System | schneider-electric | modicon_140cra_firmware | * | Yes |
Hardware | schneider-electric | modicon_140cra | - | No |