QID 590476

Date Published: 2021-08-10

QID 590476: Schneider Electric Modicon Controllers Multiple Vulnerabilities(ICSA-21-194-02)

AFFECTED PRODUCTS
Schneider Electric reports these vulnerabilities affect the following control products:
Modicon M580 CPU (part numbers BMEP and BMEH), all versions
Modicon M340 CPU (part numbers BMXP34), all versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may allow arbitrary code execution and loss of confidentiality and integrity of the project file.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-194-02 for affected packages and patching details. Please note not all the vulnerabilities listed below affect all the products above. See SEVD-2021-194-01 how they correlate.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-194-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-194-02