An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Existe una vulnerabilidad de divulgación de información mediante discrepancia en los servidores web embebidos en todos los Modicon M340, Premium, Quantum PLCs y BMXNOR0200, donde el servidor web envía diferentes respuestas de forma que expone información relevante para la seguridad sobre el estado del producto, como si una operación en concreto ha sido exitosa o no.
AV:N/AC:L/Au:N/C:P/I:N/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | NONE |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-200
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | modicom_m340_firmware | * | <built-in method update of dict object at 0x7e6111c1c980> | Operating System |
| schneider-electric | modicom_premium_firmware | * | <built-in method update of dict object at 0x7e6110f85400> | Operating System |
| schneider-electric | modicom_quantum_firmware | * | <built-in method update of dict object at 0x7e6134293580> | Operating System |
| schneider-electric | modicom_bmxnor0200h_firmware | * | <built-in method update of dict object at 0x7e60e8874e00> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:modicom_m340_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:modicom_m340:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:modicom_premium_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:modicom_premium:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:modicom_quantum_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:modicom_quantum:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:modicom_bmxnor0200h_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:modicom_bmxnor0200h:-:*:*:*:*:*:*:* |