QID 591036

Date Published: 2022-09-16

QID 591036: Schneider Electric Modicon PAC Controllers Vulnerability (SEVD-2022-221-04)

AFFECTED PRODUCTS
Modicon M340 CPU (part numbers BMXP34*) V3.30 and prior
Modicon M580 CPU (part numbers BMEP* and BMEH*) V3.22 and prior
Modicon MC80 (BMKC80) V1.6 and prior
Modicon Momentum MDI (171CBU*) V2.3 and prior
Legacy Modicon Quantum All versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability may risk read access to memory content of the controllers, which could result in exposure of sensitive information such as application password hash and project data to the attacker.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2022-221-04 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591036

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2022-221-04 URL Logo www.se.com/in/en/download/document/SEVD-2022-221-04/