Lucene search

K
cveIcscertCVE-2014-0754
HistoryOct 03, 2014 - 6:55 p.m.

CVE-2014-0754

2014-10-0318:55:06
CWE-22
icscert
web.nvd.nist.gov
54
schneiderweb
schneider electric
modicon
plc
ethernet
vulnerability
directory traversal
cve-2014-0754
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.006

Percentile

79.3%

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.

Affected configurations

Nvd
Node
schneider-electricstbnic2212_firmwareMatch-
AND
schneider-electricstbnic2212Match-
Node
schneider-electricstbnip2212_firmwareMatch-
AND
schneider-electricstbnip2212Match-
Node
schneider-electrictsxetc0101_firmwareMatch-
AND
schneider-electrictsxetc0101Match-
Node
schneider-electrictsxetc100_firmwareMatch-
AND
schneider-electrictsxetc100Match-
Node
schneider-electrictsxp573623mc_firmwareMatch-
AND
schneider-electrictsxp573623mcMatch-
Node
schneider-electrictsxety110ws_firmwareMatch-
AND
schneider-electrictsxety110wsMatch-
Node
schneider-electrictsxp574634m_firmwareMatch-
AND
schneider-electrictsxp574634mMatch-
Node
schneider-electrictsxety110wsc_firmwareMatch-
AND
schneider-electrictsxety110wscMatch-
Node
schneider-electrictsxp574823am_firmwareMatch-
AND
schneider-electrictsxp574823amMatch-
Node
schneider-electrictsxety4103_firmwareMatch-
AND
schneider-electrictsxety4103Match-
Node
schneider-electrictsxp574823m_firmwareMatch-
AND
schneider-electrictsxp574823mMatch-
Node
schneider-electrictsxety4103c_firmwareMatch-
AND
schneider-electrictsxety4103cMatch-
Node
schneider-electrictsxp574823mc_firmwareMatch-
AND
schneider-electrictsxp574823mcMatch-
Node
schneider-electrictsxety5103_firmwareMatch-
AND
schneider-electrictsxety5103Match-
Node
schneider-electrictsxp575634m_firmwareMatch-
AND
schneider-electrictsxp575634mMatch-
Node
schneider-electrictsxety5103c_firmwareMatch-
AND
schneider-electrictsxety5103cMatch-
Node
schneider-electrictsxp576634m_firmwareMatch-
AND
schneider-electrictsxp576634mMatch-
Node
schneider-electrictsxetz410_firmwareMatch-
AND
schneider-electrictsxetz410Match-
Node
schneider-electrictsxwmy100_firmwareMatch-
AND
schneider-electrictsxwmy100Match-
Node
schneider-electrictsxetz510_firmwareMatch-
AND
schneider-electrictsxetz510Match-
Node
schneider-electrictsxwmy100c_firmwareMatch-
AND
schneider-electrictsxwmy100cMatch-
Node
schneider-electrictsxntp100_firmwareMatch-
AND
schneider-electrictsxntp100Match-
Node
schneider-electricmodicon_m580_bmxnoc0402_firmwareMatch-
AND
schneider-electricmodicon_m580_bmxnoc0402Match-
Node
schneider-electricmodicon_m340_bmxnoe0100_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnoe0100Match-
Node
schneider-electricmodicon_m340_bmxnoe0110_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnoe0110Match-
Node
schneider-electricmodicon_m340_bmxnoe0110h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnoe0110hMatch-
Node
schneider-electricmodicon_m340_bmxnor0200h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnor0200hMatch-
Node
schneider-electricmodicon_m340_bmxp342020_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342020Match-
Node
schneider-electricmodicon_m340_bmxp342020h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342020hMatch-
Node
schneider-electricmodicon_m340_bmxp342030_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342030Match-
Node
schneider-electricmodicon_m340_bmxp3420302_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp3420302Match-
Node
schneider-electricmodicon_m340_bmxp3420302h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp3420302hMatch-
Node
schneider-electricmodicon_m340_bmxp342030h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342030hMatch-
Node
schneider-electricmodicon_m340_bmxnoc0401_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnoc0401Match-
Node
schneider-electric171ccc96020_firmwareMatch-
AND
schneider-electric171ccc96020Match-
Node
schneider-electric171ccc96020c_firmwareMatch-
AND
schneider-electric171ccc96020cMatch-
Node
schneider-electric171ccc96030_firmwareMatch-
AND
schneider-electric171ccc96030Match-
Node
schneider-electric171ccc96030c_firmwareMatch-
AND
schneider-electric171ccc96030cMatch-
Node
schneider-electric171ccc98020_firmwareMatch-
AND
schneider-electric171ccc98020Match-
Node
schneider-electric171ccc98030_firmwareMatch-
AND
schneider-electric171ccc98030Match-
Node
schneider-electricmodicon_m340_bmxnoc0401_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnoc0401Match-
Node
schneider-electricmodicon_m580_bmxnoc0402_firmwareMatch-
AND
schneider-electricmodicon_m580_bmxnoc0402Match-
Node
schneider-electricmodicon_m340_bmxnoe0110_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnoe0110Match-
Node
schneider-electricmodicon_m340_bmxnoe0110h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnoe0110hMatch-
Node
schneider-electricmodicon_m340_bmxnor0200h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxnor0200hMatch-
Node
schneider-electricmodicon_m340_bmxp342020_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342020Match-
Node
schneider-electricmodicon_m340_bmxp342020h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342020hMatch-
Node
schneider-electricmodicon_m340_bmxp3420302_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp3420302Match-
Node
schneider-electricmodicon_m340_bmxp342030_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342030Match-
Node
schneider-electricmodicon_m340_bmxp3420302h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp3420302hMatch-
Node
schneider-electricmodicon_m340_bmxp342030h_firmwareMatch-
AND
schneider-electricmodicon_m340_bmxp342030hMatch-
Node
schneider-electrictsxetc100_firmwareMatch-
AND
schneider-electrictsxetc100Match-
Node
schneider-electrictsxp573623mc_firmwareMatch-
AND
schneider-electrictsxp573623mcMatch-
Node
schneider-electrictsxety110ws_firmwareMatch-
AND
schneider-electrictsxety110wsMatch-
Node
schneider-electrictsxp574634m_firmwareMatch-
AND
schneider-electrictsxp574634mMatch-
Node
schneider-electrictsxety110wsc_firmwareMatch-
AND
schneider-electrictsxety110wscMatch-
Node
schneider-electrictsxp574823am_firmwareMatch-
AND
schneider-electrictsxp574823amMatch-
Node
schneider-electrictsxety4103_firmwareMatch-
AND
schneider-electrictsxety4103Match-
Node
schneider-electrictsxp574823m_firmwareMatch-
AND
schneider-electrictsxp574823mMatch-
Node
schneider-electrictsxety4103c_firmwareMatch-
AND
schneider-electrictsxety4103cMatch-
Node
schneider-electrictsxp574823mc_firmwareMatch-
AND
schneider-electrictsxp574823mcMatch-
Node
schneider-electrictsxety5103_firmwareMatch-
AND
schneider-electrictsxety5103Match-
Node
schneider-electrictsxp575634m_firmwareMatch-
AND
schneider-electrictsxp575634mMatch-
Node
schneider-electrictsxety5103c_firmwareMatch-
AND
schneider-electrictsxety5103cMatch-
Node
schneider-electrictsxp576634m_firmwareMatch-
AND
schneider-electrictsxp576634mMatch-
Node
schneider-electrictsxetz410_firmwareMatch-
AND
schneider-electrictsxetz410Match-
Node
schneider-electrictsxwmy100_firmwareMatch-
AND
schneider-electrictsxwmy100Match-
Node
schneider-electrictsxetz510_firmwareMatch-
AND
schneider-electrictsxetz510Match-
Node
schneider-electrictsxwmy100c_firmwareMatch-
AND
schneider-electrictsxwmy100cMatch-
Node
schneider-electrictsxntp100_firmwareMatch-
AND
schneider-electrictsxntp100Match-
Node
schneider-electrictsxp571634m_firmwareMatch-
AND
schneider-electrictsxp571634mMatch-
Node
schneider-electrictsxp572634m_firmwareMatch-
AND
schneider-electrictsxp572634mMatch-
Node
schneider-electrictsxp573634m_firmwareMatch-
AND
schneider-electrictsxp573634mMatch-
VendorProductVersionCPE
schneider-electricstbnic2212_firmware-cpe:2.3:o:schneider-electric:stbnic2212_firmware:-:*:*:*:*:*:*:*
schneider-electricstbnic2212-cpe:2.3:h:schneider-electric:stbnic2212:-:*:*:*:*:*:*:*
schneider-electricstbnip2212_firmware-cpe:2.3:o:schneider-electric:stbnip2212_firmware:-:*:*:*:*:*:*:*
schneider-electricstbnip2212-cpe:2.3:h:schneider-electric:stbnip2212:-:*:*:*:*:*:*:*
schneider-electrictsxetc0101_firmware-cpe:2.3:o:schneider-electric:tsxetc0101_firmware:-:*:*:*:*:*:*:*
schneider-electrictsxetc0101-cpe:2.3:h:schneider-electric:tsxetc0101:-:*:*:*:*:*:*:*
schneider-electrictsxetc100_firmware-cpe:2.3:o:schneider-electric:tsxetc100_firmware:-:*:*:*:*:*:*:*
schneider-electrictsxetc100-cpe:2.3:h:schneider-electric:tsxetc100:-:*:*:*:*:*:*:*
schneider-electrictsxp573623mc_firmware-cpe:2.3:o:schneider-electric:tsxp573623mc_firmware:-:*:*:*:*:*:*:*
schneider-electrictsxp573623mc-cpe:2.3:h:schneider-electric:tsxp573623mc:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 861

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.006

Percentile

79.3%

Related for CVE-2014-0754