
CVE-2021-22792
https://notcve.org/view.php?id=CVE-2021-22792
02 Sep 2021 — A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including ... • https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-04 • CWE-476: NULL Pointer Dereference •

CVE-2021-22791
https://notcve.org/view.php?id=CVE-2021-22791
02 Sep 2021 — A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all U... • https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-04 • CWE-787: Out-of-bounds Write •

CVE-2021-22790
https://notcve.org/view.php?id=CVE-2021-22790
02 Sep 2021 — A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Un... • https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-04 • CWE-125: Out-of-bounds Read •

CVE-2021-22789
https://notcve.org/view.php?id=CVE-2021-22789
02 Sep 2021 — A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simula... • https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-04 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0664
https://notcve.org/view.php?id=CVE-2013-0664
04 Apr 2013 — The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests. El servicio FactoryCast en los módulos Electric Quantum 140NOE77111 y 140NWM10000, M340 BMXNOE0110x, y Premium TSXETY5103 PLC , permite a usuarios autenticados remotamente el envío de mensajes Modbus, y por consiguie... • http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdf •

CVE-2013-0663 – Schneider Electric PLCs - Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2013-0663
04 Apr 2013 — Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials. Vulnerabilidad CSRF en los módulos Schneider Electric Quantum 140NOE77111, 140NOE77101, y 140NWM10000; M340 BMXNOC0401, BMX... • https://packetstorm.news/files/id/147715 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2012-0929
https://notcve.org/view.php?id=CVE-2012-0929
28 Jan 2012 — Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the (1) FTP server or (2) HTTP server. Múltiples desbordamientos de búfer en los PLCs 'Modicon Quantum' de Schneider Electric permiten a atacantes remotos provocar una denegación de servicio a través de solicitudes mal formadas al (1) servidor FTP o (2) al servidor HTTP. • http://secunia.com/advisories/47723 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-0931
https://notcve.org/view.php?id=CVE-2012-0931
28 Jan 2012 — Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors. Schneider Electric Modicon Quantum PLC no autentica la conexión entre el software de la unidad y el PLC, lo que permite a atacantes remotos provocar una denegación de servicio o ejecutar código de su elección a través de vectores no especificados. • http://secunia.com/advisories/47723 • CWE-287: Improper Authentication •

CVE-2012-0930
https://notcve.org/view.php?id=CVE-2012-0930
28 Jan 2012 — Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en PLCs Modicon Quantum de Schneider Electric permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://secunia.com/advisories/47723 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •