The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPU version 3.30 and prior
- Schneider Electric Modicon M580 CPU version 3.22 and prior
- Schneider Electric Modicon MC80 version 1.6 and prior
- Schneider Electric Modicon MOMENTUM CPU version 2.3 and prior
- Schneider Electric Legacy Modicon Quantum all versions
- Schneider Electric Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) Versions prior to SV4.21
- Summary
- A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol.
- Remediation
- Firmware V3.40 of Modicon includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/BMXP34xxxxx_SV_xx.xx/
