QID 590823

Date Published: 2022-05-06

QID 590823: Schneider Electric Ethernet and Web server on Modicon M340 controller and Communication Modules Multiple Vulnerabilities (SEVD-2022-011-01)

AFFECTED PRODUCTS
Modicon M340 CPUs: BMXP34X All versions
Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65X All versions
Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57X All versions
Modicon M340 ethernet modules:BMXNOC0401,BMXNOE01X,BMXNOR0200H All versions
Modicon Quantum and Premium factory cast communication modules:140NOE77111,140NOC78X00,TSXETY5103,TSXETY4103 All versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability may risk disclosure of sensitive information, unauthorized web server actions and denial of service.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2022-011-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590823

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2022-011-01 URL Logo www.se.com/ww/en/download/document/SEVD-2022-011-01/