QID 591325

Date Published: 2023-02-03

QID 591325: Schneider Electric Modicon PLCs Improper Check for Unusual or Exceptional Conditions Vulnerability (SEVD-2023-010-05)

AFFECTED PRODUCTS
Modicon M340 CPU (part numbers BMXP34*): All Versions
Modicon M580 CPU (part numbers BMEP* and BMEH*): All Versions
Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S): All Versions
Modicon Momentum Unity M1E Processor (171CBU*): All Versions
Modicon MC80 (BMKC80): All Versions
Legacy Modicon Quantum (140CPU65*) and Premium CPUs (TSXP57*): All Versions

QID Detection Logic:
This QID checks for the Vulnerable version of Schneider Electric Modicon PLCs using passive scanning

Successful exploitation of these vulnerabilities may risk unauthorized access to your PLC, which could result in the possibility of denial of service and loss of confidentiality, integrity of the controller.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution

    Customers are advised to refer to Schneider Electric MITIGATIONS section SEVD-2023-010-05 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591325

    Software Advisories
    Advisory ID Software Component Link