cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2020-7534,https://securityvulnerability.io/vulnerability/CVE-2020-7534,Cross-Site Request Forgery Vulnerability in Modicon CPUs by Schneider Electric,"A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Schneider Electric's Modicon CPUs, which could potentially allow attackers to execute unauthorized actions and expose sensitive information while a user is logged into the web server. This vulnerability affects various models including Modicon M340, Quantum, and Premium CPUs with integrated Ethernet, as well as specific ethernet modules and communication modules. Proper safeguards should be implemented to mitigate the risks associated with this vulnerability.",Schneider Electric,"Modicon M340 Cpus: Bmxp34 (all Versions), Modicon Quantum Cpus With Integrated Ethernet (copro): 140cpu65 (all Versions), Modicon Premium Cpus With Integrated Ethernet (copro): Tsxp57 (all Versions), Modicon M340 Ethernet Modules: (bmxnoc0401, Bmxnoe01, Bmxnor0200h) (all Versions), Modicon Quantum And Premium Factory Cast Communication Modules: (140noe77111, 140noc78*00, Tsxety5103, Tsxety4103)",8.8,HIGH,0.0007300000288523734,false,,false,false,false,,,false,false,,2022-02-04T22:29:36.000Z,0 CVE-2011-4861,https://securityvulnerability.io/vulnerability/CVE-2011-4861,,The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502.,Schneider Electric,"Quantum Ethernet Module 140noe77101,Quantum Ethernet Module 140noe77100,Quantum Ethernet Module 140noe77111",,,0.007079999893903732,false,,false,false,false,,,false,false,,2011-12-17T11:55:00.000Z,0 CVE-2011-4860,https://securityvulnerability.io/vulnerability/CVE-2011-4860,,"The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.",Schneider Electric,"Quantum Ethernet Module 140noe77101,Quantum Ethernet Module 140noe77100,Quantum Ethernet Module 140noe77111",,,0.005030000116676092,false,,false,false,false,,,false,false,,2011-12-17T11:55:00.000Z,0 CVE-2011-4859,https://securityvulnerability.io/vulnerability/CVE-2011-4859,,"The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.",Schneider Electric,"Quantum Ethernet Module 140noe77101,Quantum Ethernet Module 140cpu65260,Quantum Ethernet Module 140cpu65160,Quantum Ethernet Module 140noe77100,Quantum Ethernet Module 140cpu65150,Quantum Ethernet Module 140noe77111",,,0.04058999940752983,false,,false,false,false,,,false,false,,2011-12-17T11:00:00.000Z,0