The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon M340 CPU versions prior to SV3.51
- Schneider Electric Modicon M580 CPU versions prior to V4.10
- Schneider Electric Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) Versions prior to SV4.21
- Schneider Electric Modicon Momentum Unity M1E Processor all versions prior to sv2.70
- Schneider Electric Modicon MC80 versions prior to SV2.0
- Schneider Electric Legacy Modicon Premium CPUs all versions
- Summary
- A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol
- Remediation
- Firmware SV4.10 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/download/document/BMEx58x0x0_SV04.10
