The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M100 all references all versions
- Schneider Electric Modicon M200 all references all versions
- Schneider Electric Modicon M221 all references all versions
- Summary
- CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M100/M200/221 controllers and broke the encryption keys.
- Remediation
- Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP. • Within the Modicon M100/M200/M221 application, the user must: o Disable all unused protocols, especially Programming protocol, as described in section "Configuring Ethernet Network" of EcoStruxure Machine Expert - Basic online help for the M100/M200/M221 PLCs. This action will prevent unintended remote programming access. o Set a password to protect the project o Set a password for read access on the controller o Set a different password for write access on the controller
