The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M580 CPU <SV4.10
- Schneider Electric Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) Versions prior to SV4.21
- Schneider Electric Modicon M340 CPU <3.50
- Schneider Electric Modicon Momentum CPU All versions <SV2.6
- Schneider Electric PLC Simulator for EcoStruxure™ Control Expert All versions
- Schneider Electric PLC Simulator for EcoStruxure™ Process Expert All versions
- Schneider Electric Legacy Modicon Premium and Quantum All versions
- Schneider Electric Modicon Premium CPU All versions
- Summary
- A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file.
- Remediation
- M340 V3.50 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/download/document/BMXP34xxxxx_SV_03.50/
