CVE-2015-7937
 
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.
Desbordamiento de buffer basado en pila en GoAhead Web Server en dispositivos Schneider Electric Modicon M340 PLC BMXNOx y BMXPx permite a atacantes remotos ejecutar código arbitrario a través de una contraseña larga en los datos de HTTP Basic Authentication.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-10-22 CVE Reserved
- 2015-12-21 CVE Published
- 2024-01-20 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/79622 | Vdb Entry | |
https://ics-cert.us-cert.gov/advisories/ICSA-15-351-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-344-01 | 2024-04-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Bmxnoc0401 Search vendor "Schneider-electric" for product "Bmxnoc0401" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Bmxnoe0100 Search vendor "Schneider-electric" for product "Bmxnoe0100" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Bmxnoe0100h Search vendor "Schneider-electric" for product "Bmxnoe0100h" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Bmxnoe0110 Search vendor "Schneider-electric" for product "Bmxnoe0110" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Bmxnoe0110h Search vendor "Schneider-electric" for product "Bmxnoe0110h" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Bmxnor0200 Search vendor "Schneider-electric" for product "Bmxnor0200" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Bmxnor0200h Search vendor "Schneider-electric" for product "Bmxnor0200h" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Bmxpra0100 Search vendor "Schneider-electric" for product "Bmxpra0100" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Modicon M340 Bmxp342020 Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342020" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Modicon M340 Bmxp342020h Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342020h" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Modicon M340 Bmxp342030 Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342030" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Modicon M340 Bmxp3420302 Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302" | - | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Modicon M340 Bmxp3420302h Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302h" | - | - |
Affected
|