commands on the webserver without authentication when sending specially crafted HTTP
requests.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 10 Jun 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-255 |
Tue, 10 Jun 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A CWE-255: Credentials Management vulnerability exists in Web Server on Modicon M340, Modicon Quantum and ModiconPremium Legacy offers and their Communication Modules (see security notification for version information) which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests. | CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests. |
| Weaknesses | CWE-287 | |
| References |
|
Subscriptions
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-06-10T08:02:15.209Z
Reserved: 2020-01-21T00:00:00.000Z
Link: CVE-2020-7533
No data.
Status : Modified
Published: 2020-12-01T15:15:12.190
Modified: 2026-06-17T03:24:57.373
Link: CVE-2020-7533
No data.
OpenCVE Enrichment
No data.
-
CWE-287
Improper Authentication
- NVD-CWE-noinfo