CVE-2015-7937
21.12.2015, 11:59
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | bmxnoc0401 | - |
schneider-electric | bmxnoe0100 | - |
schneider-electric | bmxnoe0100h | - |
schneider-electric | bmxnoe0110 | - |
schneider-electric | bmxnoe0110h | - |
schneider-electric | bmxnor0200 | - |
schneider-electric | bmxnor0200h | - |
schneider-electric | bmxpra0100 | - |
schneider-electric | modicon_m340_bmxp342020 | - |
schneider-electric | modicon_m340_bmxp342020h | - |
schneider-electric | modicon_m340_bmxp342030 | - |
schneider-electric | modicon_m340_bmxp3420302 | - |
schneider-electric | modicon_m340_bmxp3420302h | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References