Unauthenticated Command Execution Vulnerability in Modicon M340, Modicon Quantum, and Modicon Premium Legacy Web Servers

Unauthenticated Command Execution Vulnerability in Modicon M340, Modicon Quantum, and Modicon Premium Legacy Web Servers

CVE-2020-7533 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A CWE-255: Credentials Management vulnerability exists in Web Server on Modicon M340, Modicon Quantum and ModiconPremium Legacy offers and their Communication Modules (see security notification for version information) which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.

Learn more about our Web App Pen Testing.