The vendor explicitly identifies these products as affected by this CVE.
- Modicon M580 Firmware Versions prior to v2.90 installed on Modicon M580 Controller
- Modicon M340 Firmware Versions prior to v3.10 installed on Modicon M340 Controller
- Modicon MC80 Firmware Versions prior to v1.80 installed on Modicon MC80 Controller (BMKC8020301)
- Modicon Momentum Unity M1E Processor Firmware Versions prior to sv2.6 installed on Modicon Momentum Unity M1E Processor (part numbers 171CBU*) Controller
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU65150 [C] & 140CPU65160 [C]
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU65260 [C]
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU67261 [C]
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU67060 [C]
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU67160 [C]
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU67260 [C]
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU65860 [C]
- Modicon Quantum Firmware Versions prior to v3.60 installed on Modicon Quantum Controller 140CPU67861 [C]
- Summary
- CWE-248: Uncaught Exception vulnerability exists which could cause a possible denial of service when writing sensitive application variables to the controller over Modbus.
- Remediation
- Version sv4.20 of Modicon M580 includes a fix for this vulnerability and is available for download here: STEP 1: Update software and firmware. • On the engineering workstation, update to EcoStruxure Control Expert v16.0: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware • On the Modicon M580 controller, update to firmware SV4.20 or above: https://www.se.com/ww/en/product-range/62098-modicon-m580-epac/#software-and-firmware STEP 2: Update projects in EcoStruxure™ Control Expert by: • Setting up an application password in the project properties • Changing the version of the controller firmware to match the new firmware version of the target controller STEP 3: Rebuild and transfer projects in EcoStruxure™ Control Expert: • Rebuild all current projects
