QID 590484
Date Published: 2021-09-07
QID 590484: Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200 Multiple Vulnerabilities (ICSA-18-086-01)
AFFECTED PRODUCTS
The following versions of Modicon PLCs are affected:
Modicon Premium all versions,
Modicon Quantum all versions,
Modicon M340 all versions, and
Modicon X80 RTU (BMXNOR0200H) all versions.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version using passive scanning
Successful exploitation of these vulnerabilities could allow a remote unauthorized attacker access to the file transfer service on the device, which could result in arbitrary code execution or malicious firmware installation.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-18-086-01 for affected packages and patching details.
Vendor References
- ICSA-18-086-01 -
www.us-cert.gov/ics/advisories/ICSA-18-086-01
CVEs related to QID 590484
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-18-086-01 |
|