Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-25620


A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.


Published

2023-04-19T09:15:07.457

Last Modified

2024-11-21T07:49:50.757

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-754

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric modicon_m580_firmware < 4.10 Yes
Hardware schneider-electric modicon_m580 - No
Operating System schneider-electric modicon_m340_firmware < 3.51 Yes
Hardware schneider-electric modicon_m340 - No
Operating System schneider-electric modicon_momentum_unity_m1e_processor_firmware * Yes
Hardware schneider-electric modicon_momentum_unity_m1e_processor - No
Operating System schneider-electric modicon_mc80_firmware * Yes
Hardware schneider-electric modicon_mc80 - No
Operating System schneider-electric 140cpu65_firmware * Yes
Hardware schneider-electric 140cpu65 - No
Operating System schneider-electric tsxp57_firmware * Yes
Hardware schneider-electric tsxp57 - No
Operating System schneider-electric bmep58s_firmware * Yes
Hardware schneider-electric bmep58s - No
Operating System schneider-electric bmeh58s_firmware * Yes
Hardware schneider-electric bmeh58s - No

References