The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric M340 CPUs BMX P34x prior to firmware version 3.20
- Schneider Electric M340 Communication Ethernet modules BMX NOE 0100 (H) prior to version 3.3
- Schneider Electric M340 Communication Ethernet modules BMX NOE 0110 (H) prior to version 6.5
- Schneider Electric M340 Communication Ethernet modules BMX NOC 0401 prior to version 2.10
- Schneider Electric Premium processors with integrated Ethernet COPRO TSXP574634, TSXP575634, TSXP576634 prior to 6.1 version
- Schneider Electric Premium communication modules TSXETY4103 prior to version 6.2
- Schneider Electric Premium communication modules TSXETY5103 prior to version 6.4
- Schneider Electric Quantum processors with integrated Ethernet COPRO 140CPU65xxxxx prior to 6.1 version
- Schneider Electric Quantum communication modules 140NOE771x1 prior to version 7.1
- Schneider Electric Quantum communication modules 140NOC78x00 prior to version 1.74
- Schneider Electric Quantum communication modules 140NOC77101 prior to version 1.08
- Summary
- CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.
- Remediation
- https://www.se.com/en/download/document/BMXP3420302_Firmwares/
