QID 590788

Date Published: 2022-04-12

QID 590788: Schneider Electric SNMP Service on Modicon M340 and associated Communication Modules Vulnerability (SEVD-2020-343-07)

Affected Products and Versions
Modicon M340 CPUs BMXP34* versions prior to V3.30
Modicon M340 Communication Ethernet modules
BMXNOE0100 (H) versions prior to V3.4
BMXNOE0110 (H) versions prior to V6.6
BMXNOR0200H versions prior to V1.7 IR22
BMXNOC0401 all versions

QID Detection Logic (Authenticated):
The QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may risk unexpected modification of network parameters, which could result in making targeted devices unreachable.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2020-343-07 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590788

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2020-343-07 URL Logo www.se.com/ww/en/download/document/SEVD-2020-343-07/