The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M580 CPUs - BMEx58xxxxx prior to version 3.20
- Schneider Electric Modicon M340 CPUs - BMX P34x prior to version 3.30
- Schneider Electric Modicon Premium CPUs - TSXP574634, TSXP575634, TSXP576634 all versions
- Summary
- CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.
- Remediation
- These vulnerabilities are fixed in firmware version 3.20, available for all product references. Follow this link to find the right firmware file based on model used: https://www.se.com/ww/en/product-range/62098- modicon-m580/ If customers choose not to apply the remediation provided above, they should immediately apply the Modicon M580 Mitigations provided below to reduce the risk of exploit.
