The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon Controllers M241 Versions prior to 5.3.12.51
- Schneider Electric Modicon Controllers M251 Versions prior to 5.3.12.51
- Schneider Electric Modicon Controllers M258 All versions
- Schneider Electric Modicon Controllers LMC058 All versions
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted body data to the controller.
- Remediation
- Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”.
