The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric M340 CPUs BMXP34x <3.40
- Schneider Electric M340 Communication Ethernet Modules BMXNOR0200H versions prior to 1.7 IR 23
- Schneider Electric M340 X80 Communication Ethernet Modules BMXNOC0401 versions prior to 2.11
- Schneider Electric M340 Communication Ethernet modules versions prior to SV03.50
- Schneider Electric Premium processors with integrated Ethernet COPRO all versions
- Schneider Electric Premium communication modules all versions
- Schneider Electric Quantum processors with integrated Ethernet COPRO 140CPU65xxxxx all versions
- Schneider Electric Quantum communication modules all verions
- Schneider Electric M340 Communication Ethernet modules versions prior to SV06.70
- Summary
- A CWE-787: Out-of-bounds Write vulnerability exists which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.
- Remediation
- V3.40 of M340 CPUs includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/download/document/BMXP34xxxxx_SV_xx.xx/
