CVE-2020-7477

EUVD-2020-28602
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethernet – 140CPU65xxxxx (all Versions), and Premium processors with integrated Ethernet (all Versions), which could cause a Denial of Service when sending a specially crafted command over Modbus.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
schneider-electric140noe77101_firmware
𝑥
≤ 7.0
schneider-electric140noe77111_firmware
𝑥
≤ 7.0
schneider-electrictsxh5744m_firmware
*
schneider-electrictsxh5724m_firmware
*
schneider-electrictsxp576634m_firmware
*
schneider-electrictsxp57554m_firmware
*
schneider-electrictsxp575634m_firmware
*
schneider-electrictsxp57454m_firmware
*
schneider-electrictsxp574634m_firmware
*
schneider-electrictsxp573634m_firmware
*
schneider-electrictsxp57304m_firmware
*
schneider-electrictsxp57254m_firmware
*
schneider-electrictsxp572634m_firmware
*
schneider-electrictsxp57204m_firmware
*
schneider-electrictsxp571634m_firmware
*
schneider-electrictsxp57154m_firmware
*
schneider-electrictsxp57104m_firmware
*
schneider-electric140cpu65150_firmware
*
schneider-electric140cpu65160_firmware
*
schneider-electric140cpu65260_firmware
*
schneider-electric140cpu67261_firmware
*
schneider-electric140cpu67060_firmware
*
schneider-electric140cpu67160_firmware
*
schneider-electric140cpu67261_firmware
*
schneider-electric140cpu67260_firmware
*
schneider-electric140cpu65860_firmware
*
schneider-electric140cpu67861_firmware
*
schneider-electric140cpu65160s_firmware
*
schneider-electric140cpu67160s_firmware
*
𝑥
= Vulnerable software versions