CVE-2015-7937

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
schneider-electricbmxnoc0401
-
schneider-electricbmxnoe0100
-
schneider-electricbmxnoe0100h
-
schneider-electricbmxnoe0110
-
schneider-electricbmxnoe0110h
-
schneider-electricbmxnor0200
-
schneider-electricbmxnor0200h
-
schneider-electricbmxpra0100
-
schneider-electricmodicon_m340_bmxp342020
-
schneider-electricmodicon_m340_bmxp342020h
-
schneider-electricmodicon_m340_bmxp342030
-
schneider-electricmodicon_m340_bmxp3420302
-
schneider-electricmodicon_m340_bmxp3420302h
-
𝑥
= Vulnerable software versions