A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in
Published Feb 4, 2022
8.8
HIGHCVSS 3.1
EPSS 0.36%
Description
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) (All Versions)
Affected products
No data.
Configuration 1
Running on/with
- n/a
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
Running on/with
- n/a
Configuration 4
- n/a
Running on/with
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- n/a
Running on/with
- n/a
Configuration 8
- n/a
Running on/with
- n/a
Configuration 9
- n/a
Running on/with
- n/a
Configuration 10
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01 x_refsource_MISCPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28659 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-01 | x_refsource_MISCPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28659 | Advisory |
Change history (0)
No recorded changes yet.