Schneider Electric
Published Oct 3, 2014
10.0
HIGHCVSS 2.0
EPSS 8.98%
Description
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.
Affected products
- Vendor Schneider Electric Product Ethernet modules for M340, Quantum and Premium PLC ranges Defaultunaffected
- Version 140CPU65150StatusaffectedConstraints-
- Version 140CPU65160StatusaffectedConstraints-
- Version 140CPU65260StatusaffectedConstraints-
- Version 140NOC77100StatusaffectedConstraints-
- Version 140NOC78000StatusaffectedConstraints-
- Version 140NOC78100StatusaffectedConstraints-
- Version 140NOE77100StatusaffectedConstraints-
- Version 140NOE77101StatusaffectedConstraints-
- Version 140NOE77101CStatusaffectedConstraints-
- Version 140NOE77110StatusaffectedConstraints-
- Version 140NOE77111StatusaffectedConstraints-
- Version 140NOE77111CStatusaffectedConstraints-
- Version 140NWM10000StatusaffectedConstraints-
- Version 170ENT11001StatusaffectedConstraints-
- Version 170ENT11002StatusaffectedConstraints-
- Version 170ENT11002CStatusaffectedConstraints-
- Version BMXNOC0401StatusaffectedConstraints-
- Version BMXNOC0402StatusaffectedConstraints-
- Version BMXNOE0100StatusaffectedConstraints-
- Version BMXNOE0110StatusaffectedConstraints-
- Version BMXNOE0110HStatusaffectedConstraints-
- Version BMXNOR0200HStatusaffectedConstraints-
- Version BMXP342020StatusaffectedConstraints-
- Version BMXP342020HStatusaffectedConstraints-
- Version BMXP342030StatusaffectedConstraints-
- Version BMXP3420302StatusaffectedConstraints-
- Version BMXP3420302HStatusaffectedConstraints-
- Version BMXP342030HStatusaffectedConstraints-
- Version BMXPRMxxxxStatusaffectedConstraints-
- Version STBNIC2212StatusaffectedConstraints-
- Version STBNIP2212StatusaffectedConstraints-
- Version TSXETC0101StatusaffectedConstraints-
- Version TSXETC100StatusaffectedConstraints-
- Version TSXETY110WSStatusaffectedConstraints-
- Version TSXETY110WSCStatusaffectedConstraints-
- Version TSXETY4103StatusaffectedConstraints-
- Version TSXETY4103CStatusaffectedConstraints-
- Version TSXETY5103StatusaffectedConstraints-
- Version TSXETY5103CStatusaffectedConstraints-
- Version TSXETZ410StatusaffectedConstraints-
- Version TSXETZ510StatusaffectedConstraints-
- Version TSXNTP100StatusaffectedConstraints-
- Version TSXP571634MStatusaffectedConstraints-
- Version TSXP572623MStatusaffectedConstraints-
- Version TSXP572623MCStatusaffectedConstraints-
- Version TSXP572634MStatusaffectedConstraints-
- Version TSXP572823MStatusaffectedConstraints-
- Version TSXP572823MCStatusaffectedConstraints-
- Version TSXP573623AMStatusaffectedConstraints-
- Version TSXP573623MStatusaffectedConstraints-
- Version TSXP573623MCStatusaffectedConstraints-
- Version TSXP573634MStatusaffectedConstraints-
- Version TSXP574634MStatusaffectedConstraints-
- Version TSXP574823AMStatusaffectedConstraints-
- Version TSXP574823MStatusaffectedConstraints-
- Version TSXP574823MCStatusaffectedConstraints-
- Version TSXP575634MStatusaffectedConstraints-
- Version TSXP576634MStatusaffectedConstraints-
- Version TSXWMY100StatusaffectedConstraints-
- Version TSXWMY100CStatusaffectedConstraints-
- Version
- Vendor Schneider Electric Product Ethernet modules for M340, Quantum and Premium PLC ranges Defaultunaffected
- Version 171CCC96020StatusaffectedConstraints-
- Version 171CCC96020CStatusaffectedConstraints-
- Version 171CCC96030StatusaffectedConstraints-
- Version 171CCC96030CStatusaffectedConstraints-
- Version 171CCC98020StatusaffectedConstraints-
- Version 171CCC98030StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Schneider Electric | Ethernet modules for M340, Quantum and Premium PLC ranges | unaffected |
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Schneider Electric | Ethernet modules for M340, Quantum and Premium PLC ranges | unaffected |
|
Configuration 1
- n/a
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- n/a
Running on/with
- n/a
Configuration 8
- n/a
Running on/with
- n/a
Configuration 9
- n/a
Running on/with
- n/a
Configuration 10
- n/a
Running on/with
- n/a
Configuration 11
- n/a
Running on/with
- n/a
Configuration 12
- n/a
Running on/with
- n/a
Configuration 13
- n/a
Running on/with
- n/a
Configuration 14
- n/a
Running on/with
- n/a
Configuration 15
- n/a
Running on/with
- n/a
Configuration 16
- n/a
Running on/with
- n/a
Configuration 17
- n/a
Running on/with
- n/a
Configuration 18
- n/a
Running on/with
- n/a
Configuration 19
- n/a
Running on/with
- n/a
Configuration 20
- n/a
Running on/with
- n/a
Configuration 21
- n/a
Running on/with
- n/a
Configuration 22
- n/a
Running on/with
- n/a
Configuration 23
Running on/with
- n/a
Configuration 24
Running on/with
- n/a
Configuration 25
Running on/with
- n/a
Configuration 26
Running on/with
- n/a
Configuration 27
Running on/with
- n/a
Configuration 28
Running on/with
- n/a
Configuration 29
Running on/with
- n/a
Configuration 30
Running on/with
- n/a
Configuration 31
Running on/with
- n/a
Configuration 32
Running on/with
- n/a
Configuration 33
Running on/with
- n/a
Configuration 34
Running on/with
- n/a
Configuration 35
- n/a
Running on/with
- n/a
Configuration 36
- n/a
Running on/with
- n/a
Configuration 37
- n/a
Running on/with
- n/a
Configuration 38
- n/a
Running on/with
- n/a
Configuration 39
- n/a
Running on/with
- n/a
Configuration 40
- n/a
Running on/with
- n/a
Configuration 41
Running on/with
- n/a
Configuration 42
Running on/with
- n/a
Configuration 43
Running on/with
- n/a
Configuration 44
Running on/with
- n/a
Configuration 45
Running on/with
- n/a
Configuration 46
Running on/with
- n/a
Configuration 47
Running on/with
- n/a
Configuration 48
Running on/with
- n/a
Configuration 49
Running on/with
- n/a
Configuration 50
Running on/with
- n/a
Configuration 51
Running on/with
- n/a
Configuration 52
- n/a
Running on/with
- n/a
Configuration 53
- n/a
Running on/with
- n/a
Configuration 54
- n/a
Running on/with
- n/a
Configuration 55
- n/a
Running on/with
- n/a
Configuration 56
- n/a
Running on/with
- n/a
Configuration 57
- n/a
Running on/with
- n/a
Configuration 58
- n/a
Running on/with
- n/a
Configuration 59
- n/a
Running on/with
- n/a
Configuration 60
- n/a
Running on/with
- n/a
Configuration 61
- n/a
Running on/with
- n/a
Configuration 62
- n/a
Running on/with
- n/a
Configuration 63
- n/a
Running on/with
- n/a
Configuration 64
- n/a
Running on/with
- n/a
Configuration 65
- n/a
Running on/with
- n/a
Configuration 66
- n/a
Running on/with
- n/a
Configuration 67
- n/a
Running on/with
- n/a
Configuration 68
- n/a
Running on/with
- n/a
Configuration 69
- n/a
Running on/with
- n/a
Configuration 70
- n/a
Running on/with
- n/a
Configuration 71
- n/a
Running on/with
- n/a
Configuration 72
- n/a
Running on/with
- n/a
Configuration 73
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Please see Schneider Electric’s vulnerability disclosure (SEVD-2014-260-01)Schneider Electric Vulnerability Disclosure – Modicon Ethernet Comm Modules - SEVD-2014-260-01 - http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2014-260-01 . for more detailed information on which product part numbers are affected, as well as the complete list of which devices have released firmware updates available.
This vulnerability disclosure can be downloaded at the following URL: http://www.schneider-electric.com/ww/en/download/
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.98% (0.08978) | 95.11th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.98% (0.08978) | 94.58th | v5 (v2026.06.15) |
| Jan 22, 2026 | 19.84% (0.19838) | 95.27th | v4 (v2025.03.14) |
| Dec 20, 2025 | 16.67% (0.16667) | 94.70th | v4 (v2025.03.14) |
| Aug 26, 2025 | 2.25% (0.02251) | 83.92th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.41% (0.05406) | 89.16th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.13% (0.10128) | 88.41th | v4 (v2025.03.14) |
| Mar 19, 2025 | 5.57% (0.05568) | 89.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.16% (0.07164) | 90.91th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.64% (0.00642) | 79.94th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.64% (0.00642) | 78.59th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.64% (0.00642) | 76.05th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.14% (0.01136) | 59.45th | v2 (v2022.01.01) |
| Oct 18, 2022 | 1.14% (0.01136) | 58.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.14% (0.01136) | 56.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.14% (0.01136) | 34.23th | v2 (v2022.01.01) |
References (5)
- http://download.schneider-electric.com/files?p_Reference=SEVD-2014-260-01&p_EnDocType=Software%20-%20Updates&p_File_Id=608959359&p_File_Name=SEVD-2014-260-01.pdf PatchVendor Advisory
- http://www.securityfocus.com/bid/70193 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2014-260-01
- https://ics-cert.us-cert.gov/advisories/ICSA-14-273-01 Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-273-01
| Link | Providers | Tags |
|---|---|---|
| http://download.schneider-electric.com/files?p_Reference=SEVD-2014-260-01&p_EnDocType=Software%20-%20Updates&p_File_Id=608959359&p_File_Name=SEVD-2014-260-01.pdf | PatchVendor Advisory | |
| http://www.securityfocus.com/bid/70193 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2014-260-01 | ||
| https://ics-cert.us-cert.gov/advisories/ICSA-14-273-01 | Third Party AdvisoryUS Government Resource | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-14-273-01 |
Change history (0)
No recorded changes yet.