The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPUs BMXP34* versions prior to v3.50
- Schneider Electric Modicon M340 X80 Ethernet Communication modules BMXNOE0100 (H) versions prior to SV03.50
- Modicon M340 X80 Ethernet Communication modules 1.7 IR24
- Schneider Electric Modicon M340 X80 Ethernet Communication modules BMXNOE0110 (H) versions prior to SV06.70
- Summary
- A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP.
- Remediation
- Version 3.50 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/BMXP34xxxxx_SV_03. 50/ If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 161/UDP. • Configure the Access Control List following the recommendations of the user manual “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31007131K010 00/ • Setup a VPN between the Modicon PLC impacted modules and the engineering workstation containing EcoStruxure Control Expert.
