QID 590486

Date Published: 2021-08-10

QID 590486: Schneider Electric Modicon M221 PLCs Multiple Vulnerabilities(ICSA-17-103-02A)

AFFECTED PRODUCTS
Schneider Electric reports that these vulnerabilities affect the following PLCs and tools for configuring and developing automation machinery:
All Modicon M221 PLCs with firmware version up to v1.5.0.1 .

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

One vulnerability may allow an attacker to extract a protected project file from the controller to obtain sensitive project information. The second vulnerability may allow a user with access to a protected project file to decrypt it in order to obtain sensitive information without authorization.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-17-103-02A for affected packages and patching details.

    Vendor References

    CVEs related to QID 590486

    Software Advisories
    Advisory ID Software Component Link
    ICSA-17-103-02A URL Logo www.us-cert.gov/ics/advisories/ICSA-17-103-02A