The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Modicon Controllers M241 Versions prior to 5.3.12.51
- Schneider Electric Modicon Controllers M251 Versions prior to 5.3.12.51
- Schneider Electric Modicon Controllers M262 Versions prior to 5.3.9.18
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request containing invalid data type to the webserver.
- Remediation
- Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”.
