QID 590773

Date Published: 2022-04-12

QID 590773: Schneider Electric Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules Vulnerability (SEVD-2020-343-06)

Affected Products and Versions Product Version Modicon M340 CPUs BMXP34* versions prior to V3.30 Modicon M340 Ethernet Communication modules BMXNOE0100 (H) versions prior to V3.4 Modicon M340 Ethernet Communication modules BMXNOE0110 (H) versions prior to V6.5 Modicon M340 Ethernet Communication modules BMXNOC0401 (H) all versions Modicon Quantum communication modules 140NOE771x1 versions prior to V7.3 Modicon Quantum communication modules 140NOC78x00 all versions Modicon Quantum communication modules 140NOC77101 all versions Modicon Quantum processors with integrated Ethernet COPRO 140CPU65xx0 all versions Modicon Premium communication modules TSXETY4103 all versions Modicon Premium communication modules TSXETY5103 all versions Modicon Premium processors with integrated Ethernet COPRO TSXP574634 all versions Modicon Premium processors with integrated Ethernet TSXP575634 all versions Modicon Premium processors with integrated Ethernet TSXP576634 all versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may risk a Denial of Service attack, which could result in the unavailability of the web and FTP services.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2020-343-06 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590773

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2020-343-06 URL Logo www.se.com/in/en/download/document/SEVD-2020-343-06/