ICSA-19-136-01
·
Published 2019-05-16
·
View on CISA ICS-CERT ↗
Schneider Electric Modicon Controllers
CVSS 5.4
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to hijack TCP connections or cause information leakage.
CVEs (1)
Remediations
- Modicon M580 firmware Version 2.80 is available for download. For more information see Schneider Electric advisory SEVD-2019-134-03
- Modicon M340: currently, no fix is available. Schneider Electric recommends that affected users set up network segmentation and implement a firewall to block all remote/external access to TCP ports. Configure the Access Control List following the recommendations of the user manual “Modicon M340 for Ethernet Communications Modules and Processors User Manual,” in the chapter titled “Messaging Configuration Parameters,” which is available here: https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=31007131_K01_000_16.pdf&p_Doc_Ref=31007131K01000
- Schneider Electric recommends that affected users set up network segmentation and implement a firewall to block all remote/external access to TCP ports.
- Configure the Access Control List following the recommendations of the user manual “Modicon M340 for Ethernet Communications Modules and Processors User Manual,” in the chapter titled “Messaging Configuration Parameters,” which is available here: https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=31007131_K01_000_16.pdf&p_Doc_Ref=31007131K01000
- Modicon Premium and Modicon Quantum: Set up network segmentation and implement a firewall to block all unauthorized access to all TCP ports.
- Set up network segmentation and implement a firewall to block all unauthorized access to all TCP ports.
- In December 2018, Schneider Electric reported that the Modicon Premium and Quantum controllers reached the End of Commercialization life cycle. For more information, please see Schneider Electric advisory SEVD-2019-134-03
Affected Vendors
Schneider Electric Software, LLC
Affected Products (4)
Schneider Electric Software, LLC
·
Modicon Premium
vers:all/*
Schneider Electric Software, LLC
·
Modicon M580
< 2.30
Schneider Electric Software, LLC
·
Modicon Quantum
vers:all/*
Schneider Electric Software, LLC
·
Modicon M340
vers:all/*
Affected Sectors
Multiple Sectors
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more