QID 590767

Date Published: 2022-04-12

QID 590767: Schneider Electric Modicon M580 Controller Vulnerability (SEVD-2019-190-03)

Affected Product(s)
Modicon M580 CPU - BMEP582040 all versions before V2.90
Modicon Ethernet Module BMENOC0301 all versions before V2.16

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

A CWE-119 Buffer Errors vulnerability exists which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2019-190-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590767

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2019-190-03 URL Logo www.se.com/ww/en/download/document/SEVD-2019-190-03/