The vendor explicitly identifies these products as affected by this CVE.
- Modicon M340 CPU Firmware Versions prior to SV3.65 installed on Modicon M340 CPU Controller (part numbers BMXP34*)
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could lead to tampering a parameter of the controller memory after a successful Man In The Middle attack followed by Read Physical Memory operation leading to loss of confidentiality of controller memory.
- Remediation
- Version SV3.65 of Modicon M340 firmware includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/1468- modicon-m340
