CyberSec.Space Logo
Back to CVE Browser

CVE-2015-7937

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1780%
EPSS Percentile27.68th
PublishedDec 21, 2015
Last ModifiedMay 6, 2026

Vulnerability Description

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.

Affected Platforms (CPE)

πŸ”Œ
Schneider Electric

Bmxnoc0401

All versions
πŸ”Œ
Schneider Electric

Bmxnoe0100

All versions
πŸ”Œ
Schneider Electric

Bmxnoe0100h

All versions
πŸ”Œ
Schneider Electric

Bmxnoe0110

All versions
πŸ”Œ
Schneider Electric

Bmxnoe0110h

All versions
πŸ”Œ
Schneider Electric

Bmxnor0200

All versions
πŸ”Œ
Schneider Electric

Bmxnor0200h

All versions
πŸ”Œ
Schneider Electric

Bmxpra0100

All versions
πŸ”Œ
Schneider Electric

Modicon M340 Bmxp342020

All versions
πŸ”Œ
Schneider Electric

Modicon M340 Bmxp342020h

All versions
πŸ”Œ
Schneider Electric

Modicon M340 Bmxp342030

All versions
πŸ”Œ
Schneider Electric

Modicon M340 Bmxp3420302

All versions
πŸ”Œ
Schneider Electric

Modicon M340 Bmxp3420302h

All versions

References & Advisories

Related Vulnerabilities