QID 590774

Date Published: 2022-04-12

QID 590774: Schneider Electric Modicon M580 Modicon M340 Legacy Controllers Modicon Quantum and Modicon Premium Multiple Vulnerabilities (SEVD-2020-343-08)

Affected Products and Versions
Modicon M580 CPUs BMEx58xxxxx prior to version 3.20 Modicon M340 CPUs BMX P34x prior to version 3.30 Modicon Premium CPUs all versions TSXP574634, TSXP575634, TSXP576634 Modicon Quantum CPUs all versions 140CPU65xxxxx

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may risk a denial of service attack, which could result in making the device enter a non-recoverable fault state

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2020-343-08 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590774

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2020-343-08 URL Logo www.se.com/in/en/download/document/SEVD-2020-343-08/