ID

VAR-201909-1551


TITLE

Schneider Electric Modicon M340 PLC Has Click Hijacking Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2019-32852

DESCRIPTION

Schneider Electric Modicon M340 is a medium-sized PLC of Schneider Electric, which is widely used in the field of industrial control in China. Schneider Electric Modicon M340 PLC has a click hijacking vulnerability. Attackers can tamper with user passwords by constructing special links

Trust: 0.72

sources: CNVD: CNVD-2019-32852 // IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f // CNVD: CNVD-2019-32852

AFFECTED PRODUCTS

vendor:schneidermodel:electric m340 plcscope: - version: -

Trust: 0.6

vendor:schneider electricmodel:m340 plcscope:eqversion:*

Trust: 0.2

sources: IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f // CNVD: CNVD-2019-32852

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-32852
value: LOW

Trust: 0.6

IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f
value: LOW

Trust: 0.2

CNVD: CNVD-2019-32852
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f // CNVD: CNVD-2019-32852

TYPE

Permission permission and access control

Trust: 0.2

sources: IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f

PATCH

title:Schneider Electric Modicon M340 PLC Has Click Hijacking Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/178813

Trust: 0.6

sources: CNVD: CNVD-2019-32852

EXTERNAL IDS

db:CNVDid:CNVD-2019-32852

Trust: 0.8

db:IVDid:0554A43F-BDC4-447A-AC95-7FCCFB49393F

Trust: 0.2

sources: IVD: 0554a43f-bdc4-447a-ac95-7fccfb49393f // CNVD: CNVD-2019-32852

SOURCES

db:IVDid:0554a43f-bdc4-447a-ac95-7fccfb49393f
db:CNVDid:CNVD-2019-32852

LAST UPDATE DATE

2022-05-17T02:03:11.276000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-32852date:2019-09-25T00:00:00

SOURCES RELEASE DATE

db:IVDid:0554a43f-bdc4-447a-ac95-7fccfb49393fdate:2019-09-24T00:00:00
db:CNVDid:CNVD-2019-32852date:2019-10-19T00:00:00