A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: schneider

Published: 2020-11-18T13:51:16

Updated: 2020-11-18T13:51:16

Reserved: 2020-01-21T00:00:00


Link: CVE-2020-7564

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-11-18T14:15:13.363

Modified: 2020-12-02T21:08:52.600


Link: CVE-2020-7564

JSON object: View

cve-icon Redhat Information

No data.

CWE