The vendor explicitly identifies these products as affected by this CVE.
- Modicon M340 CPU Firmware Versions prior to SV3.65 installed on Modicon M340 CPU Controller (part numbers BMXP34*)
- Modicon MC80 Firmware Versions prior to SV2.1 installed on Modicon MC80 Controller (part numbers BMKC80)
- Modicon Momentum Unity M1E Processor Firmware Versions prior to SV2.80 installed on Modicon Momentum Unity M1E Processor Controller (171CBU*)
- Summary
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause potential arbitrary code execution after a successful Man-In -The Middle attack followed by sending crafted Modbus command in order to tamper with a function call used to evaluate memory size.
- Remediation
- Version SV3.65 of Modicon M340 firmware includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/1468- modicon-m340
