Schneider Electric Modicon M340 Buffer Overflow Vulnerability (CVE-2015-7937)
Schneider Electric Modicon M340 Buffer Overflow Vulnerability (CVE-2015-7937)
Release date:
Updated on:
Affected Systems:
Schneider Electric Modicon PLC BMXPRA0100
Schneider Electric Modicon PLC BMXP3420302H
Schneider Electric Modicon PLC BMXP3420302
Schneider Electric Modicon PLC BMXP342030
Schneider Electric Modicon PLC BMXP342020H
Schneider Electric Modicon PLC BMXP342020
Schneider Electric Modicon PLC BMXNOR0200H
Schneider Electric Modicon PLC BMXNOR0200
Schneider Electric Modicon PLC BMXNOE0110H
Schneider Electric Modicon PLC BMXNOE0110
Schneider Electric Modicon PLC BMXNOE0100H
Schneider Electric Modicon PLC BMXNOE0100
Schneider Electric Modicon PLC BMXNOC0401
Description:
CVE (CAN) ID: CVE-2015-7937
Schneider Electric Modicon M340 PLC is a medium-sized PLC platform for industrial processes and architectures.
Schneider Electric Modicon M340 PLC BMXNOx and GoAhead Web Server of BMXPx devices have the stack buffer overflow vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code by basically verifying long passwords in data over HTTP.
<* Source: David Atch
Link: https://ics-cert.us-cert.gov/advisories/ICSA-15-351-01
*>
Suggestion:
Vendor patch:
Schneider Electric
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.schneider-electric.com/ww/en/download/document/SEVD-2015-344-01
This article permanently updates the link address: