QID 591409

Date Published: 2023-04-03

QID 591409: Schneider Electric Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and Associated Communication Modules Path Traversal Vulnerability (SEVD-2020-343-05)

AFFECTED PRODUCTS
Modicon M340 CPUs: BMXP34* versions prior to V3.30
Modicon M340 X80 Ethernet Communication modules:
BMXNOE0100 (H) prior to V3.4
BMXNOE0110 (H) prior to V6.6
BMXNOC0401 prior to V2.11
Modicon Premium processors with integrated Ethernet COPRO:
TSXP574634 all versions
TSXP575634 all versions
TSXP576634 all versions
Modicon Quantum processors with integrated Ethernet COPRO:
140CPU65xxxxx all versions
Modicon Quantum communication modules:
140NOE771x1 versions prior to V7.3
140NOC78x00 all versions
140NOC77101 all versions
Modicon Premium communication modules:
TSXETY4103 all versions
TSXETY5103 all versions

QID Detection Logic:
This QID checks for the Vulnerable version of Schneider Electric Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and Associated Communication Modules using passive scanning.

Successful exploitation of this vulnerability may risk an attack on the web server, which could result in disclosure of sensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2020-343-05 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591409

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2020-343-05 URL Logo www.se.com/in/en/download/document/SEVD-2020-343-05/