Multiple Schneider Electric Modicon PLC Modules Directory Traversal

Critical Nessus Network Monitor Plugin ID 7154


A Schneider Electric Modicon programmable logic controller (PLC) communications module containing a directory traversal vulnerability has been detected.


Schneider Electric Ethernet modules for Modicon M340, Modicon Quantum, and Modicon Premium PLCs in addition to Modicon Momentum, Modicon TSX Micro, and Modicon STB modules that provide HTTP services contain a directory traversal vulnerability. Attackers can remotely bypass web server authentication thereby achieving unauthenticated administrative access and control of the device.


See Schneider Electric's Security Advisory, SEVD-2014-260-01, for a list of firmware updates that fix this issue.

See Also

Plugin Details

Severity: Critical

ID: 7154

Version: 1.0

Family: SCADA

Published: 2014/12/03

Modified: 2018/09/16

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/h:schneider-electric

Reference Information

CVE: CVE-2014-0754

BID: 70193