QID 590473

Date Published: 2021-08-10

QID 590473: Schneider Electric Modicon Controllers (Update A) Multiple Vulnerabilities(ICSA-20-016-01)

AFFECTED PRODUCTS
The following versions of Modicon controllers, a PLC, are affected:
Following Modicon controllers are affected:
Modicon M580, all versions prior to v2.80
Modicon M340, all versions prior to v3.01
Modicon Premium, all versions prior to v3.20
Modicon Quantum, all versions prior to v3.52

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could result in a denial-of-service condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-016-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590473

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-016-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-016-01