The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric OPC UA Modicon Communication Module (BMENUA0100) version 1.10 and prior
- Schneider Electric X80 advanced RTU Communication Module (BMENOR2200H) 1.0
- Summary
- A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers.
- Remediation
- BMENUA0100 V2.01 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/download/document/BMENUA0100_FIRMWARE_SV_02.01/
