QID 590775

Date Published: 2022-04-12

QID 590775: Schneider Electric Web Server on Modicon M340, Quantum and Premium Legacy offers and their Communication Modules Vulnerability (SEVD-2020-287-01)

Schneider Electric is aware of a vulnerability in the web server of the Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their communication modules.

Affected Products and Versions
M340 CPUs BMX P34x prior to firmware version 3.20
M340 Communication Ethernet modules
BMX NOE 0100 (H) prior to version 3.3
BMX NOE 0110 (H) prior to version 6.5
BMX NOC 0401 prior to version 2.10
Premium processors with integrated Ethernet COPRO
TSXP574634, TSXP575634, TSXP576634 prior to 6.1 version
Premium communication modules
TSXETY4103 prior to version 6.2
TSXETY5103 prior to version 6.4
Quantum processors with integrated Ethernet COPRO
140CPU65xxxxx prior to 6.1 version
Quantum communication modules
140NOE771x1 prior to version 7.1
140NOC78x00 prior to version 1.74
140NOC77101 prior to version 1.08

QID Detection Logic (Authenticated):
The QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may risk execution of commands on the webserver by an authenticated attacker, which could result in loss of availability, confidentiality and integrity on the controller.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2020-287-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590775

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2020-287-01 URL Logo www.se.com/in/en/download/document/SEVD-2020-287-01/