Out-of-bounds write in Schneider Electric products - CVE-2020-7563
Published: January 7, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when uploading a specially crafted file on the controller over FTP. A remote authenticated attacker can trigger out-of-bounds write and execute arbitrary code on the target system.
This vulnerability affects the following Modicon products:
- M340 CPUs
- BMX P34x, all versions
- M340 Communication Ethernet modules
- BMX NOE 0100 (H), all versions
- BMX NOE 0110 (H), all versions
- BMX NOC 0401, all versions
- BMX NOR 0200H, all versions
- Premium processors with integrated Ethernet COPRO
- TSXP574634, TSXP575634, TSXP576634, all versions
- Premium communication modules
- TSXETY4103, all versions
- TSXETY5103, all versions
- Quantum processors with integrated Ethernet COPRO
- 140CPU65xxxxx, all versions
- Quantum communication modules
- 140NOE771x1, all versions
- 140NOC78x00, all versions
- 140NOC77101, all versions
Affected software
BMX NOE 0100 (H)
BMX NOE 0110 (H)
BMX NOC 0401
BMX NOR 0200H
TSXP574634
TSXP575634
TSXP576634
TSXETY4103
TSXETY5103
140CPU65xxxxx
140NOE771x1
140NOC78x00
140NOC77101