CVE-2013-0663
Published Apr 4, 2013
Last updated 6 years ago
Overview
- Description
- Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:schneider-electric:modicon_quantum_plc:140noe77101:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18705050-B954-4AB9-A8D0-BDCB09A9839A" }, { "criteria": "cpe:2.3:h:schneider-electric:modicon_quantum_plc:140noe77111:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "56FB594F-638A-4E8B-9072-475E64CDE999" }, { "criteria": "cpe:2.3:h:schneider-electric:modicon_quantum_plc:140nwm10000:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD53FEBF-FF81-4563-B80C-CE67ABDA233B" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:schneider-electric:modicon_m340:bmxnoc0401:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00C02342-50B0-4883-9430-9CAB7968081B" }, { "criteria": "cpe:2.3:h:schneider-electric:modicon_m340:bmxnoe011xx:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21E85599-1298-4B8C-8255-42D165F905F4" }, { "criteria": "cpe:2.3:h:schneider-electric:modicon_m340:bmxnoe0100x:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F41B43D-038F-4775-A1BB-486918806E7E" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:schneider-electric:modicon_premium:tsxety4103:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FEEA7CF9-59A9-4B40-9E20-F179D40815C9" }, { "criteria": "cpe:2.3:h:schneider-electric:modicon_premium:tsxety5103:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7579763-6663-41F7-A162-5FEBA9A9CE70" }, { "criteria": "cpe:2.3:h:schneider-electric:modicon_premium:tsxwmy100:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42C34DAA-D856-4E59-A98F-2DF47E600612" } ], "operator": "OR" } ] } ]