The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPUs BMXP34* versions prior to V3.30
- Schneider Electric Modicon M340 X80 Ethernet Communication modules BMXNOE0100 (H) prior to version 3.4
- Schneider Electric Modicon M340 X80 Ethernet Communication modules BMXNOE0110 (H) prior to version 6.6
- Schneider Electric Modicon M340 X80 Ethernet Communication modules BMXNOC0401 <V2.11
- Schneider Electric Modicon Premium processors with integrated Ethernet COPRO TSXP574634 all versions
- Schneider Electric Modicon Premium processors with integrated Ethernet COPRO TSXP575634 all versions
- Schneider Electric Modicon Premium processors with integrated Ethernet COPRO TSXP576634 all versions
- Schneider Electric Modicon Quantum processors with integrated Ethernet COPRO 140CPU65xxxxx all versions
- Schneider Electric Modicon Quantum communication modules 140NOE771x1 versions prior to V7.3
- Schneider Electric Modicon Quantum communication modules 140NOC78x00 all versions
- Schneider Electric Modicon Quantum communication modules 140NOC77101 all versions
- Schneider Electric Modicon Premium communication modules TSXETY4103 all versions
- Summary
- A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type)vulnerability exists that could cause disclosure of information when sending a specially crafted request to the controller over HTTP.
- Remediation
- Firmware V3.30 is available for all the product references. Follow this link and find the right firmware file based on model used. https://www.se.com/ww/en/product-range/1468-modicon-m340/?parent-subcategory-id=3950
