QID 590907

Date Published: 2022-07-18

QID 590907: Schneider Electric Embedded FTP Servers for Modicon PAC Controllers Multiple Vulnerabilities (SEVD-2018-081-01)

Affected Products
Modicon M340, V3.50
Modicon M340, versions prior to V3.50
Modicon M580, all versions
Modicon Ethernet Communication modules:
BMXNOR02x, all versions
BMXNOE01x, all versions
BMXNOC0401x, all versions
Legacy Modicon Premium and Quantum, all versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version using passive scanning

Failure to address these vulnerabilities could result in unauthorized access to your PLC and a denial of service or other malicious activity

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2018-081-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590907

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2018-081-01 URL Logo www.se.com/ww/en/download/document/SEVD-2018-081-01/