QID 590780

Date Published: 2022-04-12

QID 590780: Schneider Electric Modicon M340 Modicon M580 Vulnerability (SEVD-2020-080-01)

Affected Products
Modicon M340: all versions prior to V3.20
Modicon M580: all versions prior to V3.10

QID Detection Logic (Authenticated):
The QID checks for the Vulnerable version of using passive scanning

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists, which, if exploited, could allow attackers to transfer malicious code to the controller.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2020-080-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590780

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2020-080-01 URL Logo www.se.com/ww/en/download/document/SEVD-2020-080-01/