A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.
Una CWE-319: existe una vulnerabilidad de Transmisión de Texto Sin Cifrar de Información Confidencial en Modicon M580, Modicon M340, Modicon Premium, Modicon Quantum (todas las versiones de firmware), lo que podría causar una divulgación de información cuando se transfieren aplicaciones al controlador usando el protocolo Modbus TCP.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
AV:N/AC:L/Au:N/C:P/I:N/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | NONE |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-319
|
| [email protected] | Primary |
en
CWE-319
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | modicon_m580_firmware | * | <built-in method update of dict object at 0x7e60a8b7c3c0> | Operating System |
| schneider-electric | modicon_m340_firmware | * | <built-in method update of dict object at 0x7e610746a2c0> | Operating System |
| schneider-electric | tsxmcpc002m_firmware | * | <built-in method update of dict object at 0x7e60bbd629c0> | Operating System |
| schneider-electric | tsxmcpc512k_firmware | * | <built-in method update of dict object at 0x7e60a8b7e2c0> | Operating System |
| schneider-electric | tsxmfpp001m_firmware | * | <built-in method update of dict object at 0x7e60a8b7c440> | Operating System |
| schneider-electric | tsxmfpp002m_firmware | * | <built-in method update of dict object at 0x7e60a8b7da40> | Operating System |
| schneider-electric | tsxmfpp004m_firmware | * | <built-in method update of dict object at 0x7e610746a100> | Operating System |
| schneider-electric | tsxmfpp512k_firmware | * | <built-in method update of dict object at 0x7e60a8b7fcc0> | Operating System |
| schneider-electric | tsxmrpc001m_firmware | * | <built-in method update of dict object at 0x7e6107469680> | Operating System |
| schneider-electric | tsxmrpc002m_firmware | * | <built-in method update of dict object at 0x7e60a8b7ea00> | Operating System |
| schneider-electric | tsxmrpc003m_firmware | * | <built-in method update of dict object at 0x7e60a8b7e600> | Operating System |
| schneider-electric | tsxmrpc007m_firmware | * | <built-in method update of dict object at 0x7e610746aec0> | Operating System |
| schneider-electric | tsxmrpc01m7_firmware | * | <built-in method update of dict object at 0x7e613c47d940> | Operating System |
| schneider-electric | tsxmrpc768k_firmware | * | <built-in method update of dict object at 0x7e613c3cccc0> | Operating System |
| schneider-electric | tsxmrpf004m_firmware | * | <built-in method update of dict object at 0x7e60a8b7e840> | Operating System |
| schneider-electric | tsxmrpf008m_firmware | * | <built-in method update of dict object at 0x7e6112ccb100> | Operating System |
| schneider-electric | tsxmcpc002m_firmware | * | <built-in method update of dict object at 0x7e60a8b7fe40> | Operating System |
| schneider-electric | tsxmcpc512k_firmware | * | <built-in method update of dict object at 0x7e60a8b7e440> | Operating System |
| schneider-electric | tsxmfp0128p2_firmware | * | <built-in method update of dict object at 0x7e60a8b7dec0> | Operating System |
| schneider-electric | tsxmfp064p2_firmware | * | <built-in method update of dict object at 0x7e60eb2d86c0> | Operating System |
| schneider-electric | tsxmfpp001m_firmware | * | <built-in method update of dict object at 0x7e62aa3d0e40> | Operating System |
| schneider-electric | tsxmfpp002m_firmware | * | <built-in method update of dict object at 0x7e610746a5c0> | Operating System |
| schneider-electric | tsxmfpp004m_firmware | * | <built-in method update of dict object at 0x7e610746af00> | Operating System |
| schneider-electric | tsxmfpp224k_firmware | * | <built-in method update of dict object at 0x7e610746a480> | Operating System |
| schneider-electric | tsxmfpp384k_firmware | * | <built-in method update of dict object at 0x7e60eb2d91c0> | Operating System |
| schneider-electric | tsxmfpp512k_firmware | * | <built-in method update of dict object at 0x7e60a8b7c9c0> | Operating System |
| schneider-electric | tsxmrpc001m_firmware | * | <built-in method update of dict object at 0x7e60a8b7d480> | Operating System |
| schneider-electric | tsxmrpc002m_firmware | * | <built-in method update of dict object at 0x7e60a8b7ce00> | Operating System |
| schneider-electric | tsxmrpc003m_firmware | * | <built-in method update of dict object at 0x7e61342e5b40> | Operating System |
| schneider-electric | tsxmrpc007m_firmware | * | <built-in method update of dict object at 0x7e60a8b7dcc0> | Operating System |
| schneider-electric | tsxmrpc01m7_firmware | * | <built-in method update of dict object at 0x7e60a8b7f800> | Operating System |
| schneider-electric | tsxmrpc448k_firmware | * | <built-in method update of dict object at 0x7e60a87b6800> | Operating System |
| schneider-electric | tsxmrpc768k_firmware | * | <built-in method update of dict object at 0x7e60a87b6b80> | Operating System |
| schneider-electric | tsxmrpf004m_firmware | * | <built-in method update of dict object at 0x7e60a87b75c0> | Operating System |
| schneider-electric | tsxmrpf008m_firmware | * | <built-in method update of dict object at 0x7e60a87b5a80> | Operating System |
| schneider-electric | tsxmrpp224k_firmware | * | <built-in method update of dict object at 0x7e60a87b6280> | Operating System |
| schneider-electric | tsxmrpp384k_firmware | * | <built-in method update of dict object at 0x7e60a87b5b40> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:modicon_m580_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:modicon_m580:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:modicon_m340_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:modicon_m340:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmcpc002m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmcpc002m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmcpc512k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmcpc512k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp001m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp001m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp002m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp002m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp004m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp004m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp512k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp512k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc001m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc001m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc002m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc002m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc003m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc003m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc007m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc007m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc01m7_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc01m7:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc768k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc768k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpf004m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpf004m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpf008m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpf008m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmcpc002m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmcpc002m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmcpc512k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmcpc512k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfp0128p2_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfp0128p2:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfp064p2_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfp064p2:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp001m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp001m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp002m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp002m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp004m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp004m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp224k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp224k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp384k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp384k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmfpp512k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmfpp512k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc001m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc001m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc002m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc002m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc003m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc003m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc007m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc007m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc01m7_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc01m7:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc448k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc448k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpc768k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpc768k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpf004m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpf004m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpf008m_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpf008m:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpp224k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpp224k:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tsxmrpp384k_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tsxmrpp384k:-:*:*:*:*:*:*:* |