The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPUs versions prior to 3.30
- Schneider Electric Modicon M340 Ethernet Communication Modules versions prior to 3.4
- Schneider Electric Modicon M340 Ethernet Communication Modules BMXNOE0110 versions prior to 6.6
- Schneider Electric Modicon M340 Ethernet Communication Modules BMXNOC0401 (H) versions prior to 2.11
- Schneider Electric Modicon Quantum Communication Modules 140NOE771x1 versions prior to 7.3
- Schneider Electric Modicon Quantum Communication Modules All versions
- Schneider Electric Modicon Quantum Processors with Integrated Ethernet COPRO 140CPU65xx0 All versions
- Schneider Electric Modicon Premium Communication Modules All versions
- Schneider Electric Modicon Premium Processors with Integrated Ethernet COPRO All versions
- Summary
- A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of HTTP and FTP services when a series of specially crafted requests is sent to the controller over HTTP.
- Remediation
- Firmware V3.30 is available for all the product references. Follow this link and find the right firmware file based on model used: https://www.se.com/ww/en/product-range/1468-modiconm340/?parent-subcategory-id=3950 If customers choose not to apply the remediation, see Mitigation section.
