6.8
CVSSv2

CVE-2013-0663

Published: 04/04/2013 Updated: 24/05/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote malicious users to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric modicon quantum plc 140noe77101

schneider-electric modicon quantum plc 140nwm10000

schneider-electric modicon quantum plc 140noe77111

schneider-electric modicon m340 bmxnoe0100x

schneider-electric modicon m340 bmxnoe011xx

schneider-electric modicon m340 bmxnoc0401

schneider-electric modicon premium tsxety5103

schneider-electric modicon premium tsxwmy100

schneider-electric modicon premium tsxety4103

Exploits

# Exploit Title: Schneider Electric PLCs - Cross-Site Request Forgery # Date: 2018-05-12 # Exploit Author: t4rkd3vilz # Vendor Homepage: wwwschneider-electriccom/ # Tested on: Windows # CVE: CVE-2013-0663 # Version: Schneider Electric Quantum PLC: 140NOE77111, 140NOE77101, 140NWM10000 # Modicon M340 PLC: BMXNOC0401, BMXNOE0100x, BMXNOE011x ...
Schneider Electric PLCs suffer from a cross site request forgery vulnerability ...