Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.
                
            References
                    | Link | Resource | 
|---|---|
| http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-344-01 | Vendor Advisory | 
| http://www.securityfocus.com/bid/79622 | |
| https://ics-cert.us-cert.gov/advisories/ICSA-15-351-01 | Third Party Advisory US Government Resource | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2015-12-21 11:59
Updated : 2024-04-10 12:28
NVD link : CVE-2015-7937
Mitre link : CVE-2015-7937
CVE.ORG link : CVE-2015-7937
JSON object : View
Products Affected
                schneider-electric
- modicon_m340_bmxp342020
 - bmxnoc0401
 - bmxnoe0100h
 - modicon_m340_bmxp3420302h
 - bmxnor0200
 - modicon_m340_bmxp3420302
 - bmxpra0100
 - modicon_m340_bmxp342030
 - modicon_m340_bmxp342020h
 - bmxnoe0100
 - bmxnoe0110h
 - bmxnor0200h
 - bmxnoe0110
 
CWE
                
                    
                        
                        CWE-119
                        
            Improper Restriction of Operations within the Bounds of a Memory Buffer
