QID 590766
Date Published: 2022-04-12
QID 590766: Schneider Electric Modicon Controllers and SCADAPack RTU Vulnerability (SEVD-2017-065-01)
Affected Product(s)
Modicon Momentum M1E 171CBU98090 (All versions)
Modicon Momentum M1E 171CBU98091 (All versions)
Modicon M340 (All versions prior to V2.70)
Modicon M580 (All versions prior to V2.01)
Modicon Premium (All versions prior to V3.10)
Modicon Quantum (All versions prior to V3.12)
Modicon M221 (All versions)
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
SCADAPack 32 RTU (All Versions)
SCADAPack 300 series RTU (314, 330, 334, 350) (All Versions)
SCADAPack 300 E and 500 E series RTU (312E, 313E, 314E, 330E, 333E, 337E, 350E,530E, 535E) (All Versions)
SCADAPack 57x RTU (570, 575) (All Versions)
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.
Customers are advised to refer to CERT MITIGATIONS section SEVD-2017-065-01 for affected packages and patching details.
- SEVD-2017-065-01 -
www.se.com/ww/en/download/document/SEVD-2017-065-01/
CVEs related to QID 590766
| Advisory ID | Software | Component | Link |
|---|