QID 590493

Date Published: 2021-10-14

QID 590493: Schneider Electric Modicon PLC Multiple Vulnerabilities (ICSA-15-246-02)

AFFECTED PRODUCTS
Schneider Electric reports that the vulnerabilities affect the following Modicon PLC products:
BMXNOC0401,
BMXNOE0100,
BMXNOE0110,
BMXNOE0110H,
BMXNOR0200H,
BMXP342020,
BMXP342020H,
BMXP342030,
BMXP3420302,
BMXP3420302H, and
BMXP342030H.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An attacker exploiting these vulnerabilities can cause the client browser to redirect to a remote file or execute Java script.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-15-246-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590493

    Software Advisories
    Advisory ID Software Component Link
    ICSA-15-246-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-15-246-02