QID 590471

Date Published: 2021-09-07

QID 590471: Schneider Electric Modicon M221 Programmable Logic Controller Multiple Vulnerabilities (ICSA-20-343-04)

AFFECTED PRODUCTS
Schneider Electric reports these vulnerabilities affect the following Modicon products:
Modicon M221: All versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker to take control over the PLC and gain unauthorized access, which could result in exposure of sensitive information.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-343-04 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-343-04 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-343-04