The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Control Expert all versions prior to V15.0
- Schneider Electric Unity Pro all versions
- Schneider Electric Modicon M340 all versions prior to V3.20
- Schneider Electric Modicon M580 all versions prior to V3.10
- Summary
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists, which, if exploited, could allow attackers to transfer malicious code to the controller.
- Remediation
- After downloading the new version, found in the Download Links section below, all of the following steps are required to remediate the vulnerability: STEP 1: Update software and firmware: • On the engineering workstation: o Recommended remediation: update to EcoStruxure Control Expert V15.0 (Available in the Download Links section) • On the Modicon M340 controller: update to firmware V3.20 or above (Available in the Download Links section) • On the Modicon M580 controller: update to firmware V3.10 or above (Available in the Download Links section) STEP 2: Update projects in Ecostruxure Control Expert by: • Setting up an application password in the project properties • Changing the version of the controller firmware to match the new firmware version of the target controller STEP 3: Rebuild and transfer projects in EcoStruxure Control Expert: • Rebuild all current projects • Transfer them to Modicon controllers STEP 4: Configure the Access Controls on Modicon controllers: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP
