CVE-2015-7937

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:schneider-electric:bmxnoc0401:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoe0100:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoe0100h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoe0110:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoe0110h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnor0200:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnor0200h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxpra0100:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342030:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302h:-:*:*:*:*:*:*:*

History

10 Apr 2024, 12:28

Type Values Removed Values Added
CPE cpe:2.3:h:schneider-electric:bmxp342020:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp342020h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp3420302:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp3420302h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp342030:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342030:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302h:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020:-:*:*:*:*:*:*:*
First Time Schneider-electric modicon M340 Bmxp3420302
Schneider-electric modicon M340 Bmxp342030
Schneider-electric modicon M340 Bmxp342020
Schneider-electric modicon M340 Bmxp342020h
Schneider-electric modicon M340 Bmxp3420302h

Information

Published : 2015-12-21 11:59

Updated : 2024-04-10 12:28


NVD link : CVE-2015-7937

Mitre link : CVE-2015-7937

CVE.ORG link : CVE-2015-7937


JSON object : View

Products Affected

schneider-electric

  • bmxnoe0100
  • bmxnor0200
  • bmxnoe0110h
  • bmxnoe0100h
  • modicon_m340_bmxp3420302h
  • bmxnoc0401
  • modicon_m340_bmxp342020h
  • bmxpra0100
  • modicon_m340_bmxp3420302
  • modicon_m340_bmxp342020
  • modicon_m340_bmxp342030
  • bmxnoe0110
  • bmxnor0200h
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer