QID 590769

Date Published: 2022-07-18

QID 590769: Schneider Electric Modicon Controllers Vulnerability (SEVD-2019-134-10)

Affected Product(s)
Modicon M580 with firmware prior to V2.50
Modicon M340 with firmware prior to V3.01
BMxCRA312xx with firmware prior to V2.40
Modicon Premium - all firmware versions
140CRA312xxx - all firmware versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Buffer errors vulnerability exists when sending a specially crafted Modbus packet, which could cause a denial of service to the device that would force a restart to restore availability.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2019-134-10 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590769

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2019-134-10 URL Logo www.se.com/ww/en/download/document/SEVD-2019-134-10/