CVE-2020-7533
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
01/12/2020
Last modified:
10/06/2025
Description
CWE-287: Improper Authentication vulnerability exists which could cause the execution of<br />
commands on the webserver without authentication when sending specially crafted HTTP<br />
requests.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420302_firmware:*:*:*:*:*:*:*:* | 3.20 (excluding) | |
| cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:modicon_m340_bmxp342000_firmware:*:*:*:*:*:*:*:* | 3.20 (excluding) | |
| cpe:2.3:h:schneider-electric:modicon_m340_bmxp342000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:modicon_m340_bmxp341000_firmware:*:*:*:*:*:*:*:* | 3.20 (excluding) | |
| cpe:2.3:h:schneider-electric:modicon_m340_bmxp341000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420102_firmware:*:*:*:*:*:*:*:* | 3.20 (excluding) | |
| cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420102:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420302_firmware:*:*:*:*:*:*:*:* | 3.20 (excluding) | |
| cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:bmxnoe0100_firmware:*:*:*:*:*:*:*:* | 3.3 (excluding) | |
| cpe:2.3:h:schneider-electric:bmxnoe0100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:bmxnoe0110_firmware:*:*:*:*:*:*:*:* | 6.5 (excluding) | |
| cpe:2.3:h:schneider-electric:bmxnoe0110:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:bmxnoc0401_firmware:*:*:*:*:*:*:*:* | 2.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



