The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPUs all versions prior to V3.30
- Schneider Electric Modicon M340 Ethernet Communication modules BMXNOE0100 (H) all versions prior to V3.3
- Schneider Electric Modicon M340 Ethernet Communication modules BMXNOE0110 (H) all versions prior to V6.5
- Schneider Electric Modicon M340 Ethernet Communication modules BMXNOC0401 (H) all versions prior to V2.10
- Schneider Electric Modicon Premium communication modules TSXETY4103 prior to V6.2
- Schneider Electric Modicon Premium communication modules TSXETY4103 prior to V6.4
- Schneider Electric Modicon Premium processors with integrated Ethernet COPRO versions prior to V6.1
- Schneider Electric Modicon Quantum processors with integrated Ethernet COPRO 140CPU65xx0 prior to V6.1
- Schneider Electric Modicon Quantum communication modules 140NOE771x1, prior to V7.1
- Schneider Electric Modicon Quantum communication modules 140NOC78x00, prior to V1.74
- Schneider Electric Modicon Quantum communication modules 140NOC77101, prior to V1.08
- Schneider Electric Modicon X80 BMXNOR0200H RTU module BMXNOR0200H all versions prior to V1.70 IR 233
- Summary
- A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause unauthenticated command execution in the controller when sending special HTTP requests.
- Remediation
- Firmware V3.30 is available for all of the product references. Follow this link and find the right firmware file based on model used: https://www.se.com/ww/en/product-range/1468-modicon-m340/?parent-subcategory-id=3950
