QID 591331

Date Published: 2023-02-10

QID 591331: Schneider Electric Modicon M340, M580 CPU and M580 CPU Safety Authentication Bypass Vulnerability (SEVD-2023-010-06)

AFFECTED PRODUCTS
Modicon M340 CPU (part numbers BMXP34*): All Versions
Modicon M580 CPU (part numbers BMEP* and BMEH*): All Versions
Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S): All Versions

QID Detection Logic:
This QID checks for the Vulnerable version of Schneider Electric Modicon M340, M580 CPU and M580 CPU Safety using passive scanning.

Successful exploitation of these vulnerabilities may risk unauthorized access to your PLC, which could result in the possibility of denial of service and loss of confidentiality, integrity of the controller.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution

    Customers are advised to refer to Schneider Electric MITIGATIONS section SEVD-2023-010-06 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591331

    Software Advisories
    Advisory ID Software Component Link