QID 590469

Date Published: 2021-09-07

QID 590469: Schneider Electric Web Server on Modicon M340 Multiple Vulnerabilities (ICSA-21-005-01)

AFFECTED PRODUCTS
Schneider Electric reports these vulnerabilities affect the following Modicon products:
M340 CPUs


BMX P34x, all versions
Successful exploitation of these vulnerabilities may allow write access and the execution of commands, which could result in data corruption or a web server crash.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-005-01 for affected packages and patching details.
    M340 Communication Ethernet modulesWorkaround:

    Premium processors with integrated Ethernet COPRO

    Vendor References

    CVEs related to QID 590469

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-005-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-005-01