QID 590492

Date Published: 2021-10-14

QID 590492: Schneider Electric Modicon M340 Buffer Overflow Vulnerability Vulnerability (ICSA-15-351-01)

AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following Modicon M340 PLC products:
BMXNOC0401,
BMXNOE0100,
BMXNOE0100H,
BMXNOE0110,
BMXNOE0110H,
BMXNOR0200,
BMXNOR0200H,
BMXP342020,
BMXP342020H,
BMXP342030,
BMXP3420302,
BMXP3420302H, and
BMXPRA0100.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could cause the device that the attacker is accessing to crash; a buffer overflow condition may allow remote code execution.

  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-15-351-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590492

    Software Advisories
    Advisory ID Software Component Link
    ICSA-15-351-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-15-351-01