The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M100 all references all versions
- Schneider Electric Modicon M200 all references all versions
- Schneider Electric Modicon M221 all references all versions
- Summary
- CWE-326: Inadequate Encryption Strength vulnerability exists that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M100/M200/M221 controllers.
- Remediation
- Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP. • Within the Modicon M100/M200/M221 application, the user must: o Disable all unused protocols, especially Programming protocol, as described in section "Configuring Ethernet Network" of EcoStruxure Machine Expert - Basic online help for the M100/M200/M221 PLCs. This action will prevent unintended remote programming access. o Set a password to protect the project o Set a password for read access on the controller o Set a different password for write access on the controller
