QID 590485
Date Published: 2021-09-07
QID 590485: Schneider Electric PLCs (Update B) Multiple Vulnerabilities (ICSA-13-077-01B)
AFFECTED PRODUCTS
The following Schneider Electric products are affected:
Modicon M340 PLC modules,
Quantum PLC modules, and
Premium PLC modules.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
A malicious attacker may remotely halt, reset, or change settings for PLC modules by exploiting these vulnerabilities. This could affect products deployed in the critical manufacturing, energy, water, agriculture and food, dams, transportation, postal, nuclear, government facilities, and defense industrial sectors worldwide.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-13-077-01B for affected packages and patching details.
Vendor References
- ICSA-13-077-01B -
www.us-cert.gov/ics/advisories/ICSA-13-077-01B
CVEs related to QID 590485
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-13-077-01B |
|