The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPU <=3.40
- Schneider Electric Modicon M580 CPU <=3.22
- Schneider Electric Modicon MC80 all versions
- Schneider Electric Modicon Momentum MDI CPU <=2.5
- Schneider Electric Legacy Modicon Quantum /Premium all versions
- Schneider Electric Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)Versions prior to SV4.21
- Summary
- A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol.
- Remediation
- Firmware V3.50 of Modicon includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/BMXP34xxxxx_SV_03.50/
