The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPUs BMXP34* versions prior to 3.30
- Schneider Electric Modicon M340 X80 Communication Ethernet modules BMXNOE0100 (H) versions prior to 3.4
- Schneider Electric Modicon M340 X80 Communication Ethernet modules BMXNOE0110 (H) versions prior to 6.6
- Schneider Electric Modicon M340 X80 Communication Ethernet modules BMXNOR0200H versions prior to 1.7 IR22
- Schneider Electric Modicon M340 X80 Communication Ethernet modules BMXNOC0401 versions prior to 2.11
- Summary
- A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause the device to be unreachable when doing an unattended modification of network parameters over SNMP.
- Remediation
- Firmware V3.4 is available for download below: https://www.se.com/ww/en/download/document/BMXNOE010 Exec and Release Notes/
