QID 590767
Date Published: 2022-04-12
QID 590767: Schneider Electric Modicon M580 Controller Vulnerability (SEVD-2019-190-03)
Affected Product(s)
Modicon M580 CPU - BMEP582040 all versions before V2.90
Modicon Ethernet Module BMENOC0301 all versions before V2.16
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
A CWE-119 Buffer Errors vulnerability exists which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP CWD command with a data length greater than 1020 bytes. A power cycle is then needed to reactivate the FTP service.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2019-190-03 for affected packages and patching details.
Vendor References
- SEVD-2019-190-03 -
www.se.com/ww/en/download/document/SEVD-2019-190-03/
CVEs related to QID 590767
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2019-190-03 |
|