← Back to home
ICSA-24-326-03  ·  Published 2026-06-09  ·  View on CISA ICS-CERT ↗

Schneider Electric Modicon M340, MC80, and Momentum Unity M1E & EcoStruxure (Update A)

CVSS 7.5 HIGH

Risk Summary

Schneider Electric is aware of multiple vulnerabilities in its Modicon Controllers M340 / Momentum / MC80 / EcoStruxure™ Control Expert products. [Modicon PAC](https://www.se.com/ww/en/product-subcategory/3950-pac-programmable-automation-controllers/?filter=business-1-industrial-automation-and-control) products control and monitor industrial operations. [EcoStruxure™ Control Expert](https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#overview) is the engineering application for Modicon Controllers. Failure to apply the provided remediations/mitigations below may risk unauthorized access to the controller, which could result in the possibility of denial of service and loss of confidentiality, integrity of the controller.

Remediations

  • Firmware SV2.90 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/535-modicon-momentum/#software-and-firmware Important: Customer needs to use version of EcoStruxure™ Control Expert v16.2 HF003 minimum to connect with the latest version of Modicon Momentum.
  • EcoStruxure™ Control Expert V16.2 HF003 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware
  • Version 3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
  • Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31007131K01000/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M340 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” chapter “Controler Memory Protection”: https://www.se.com/ww/en/download/document/EIO0000001999/
  • Schneider Electric is establishing a remediation plan for all future versions of Modicon MC80 that will include a fix for CVE-2024-8933. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “MC80 Programmable Logic Controller(PLC), User Manual” in the section “Access Control List (ACL)”: https://www.se.com/ww/en/download/document/EIO0000002071/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/
  • Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Momentum for EcoStruxure™ Control Expert - 171CBU78090, 171CBU98090, 171CBU98091 Processors, User Guide” in the section “Controlling Access”: https://www.se.com/ww/en/download/document/HRB44124/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/

Affected Vendors

Schneider Electric

Affected Products (9)

Schneider Electric · Modicon M340 CPU Firmware vers:generic/<SV3.70
Schneider Electric · Modicon M340 CPU Firmware vers:generic/>=SV3.60|<SV3.70
Schneider Electric · Modicon M340 CPU Firmware vers:generic/<SV3.60
Schneider Electric · Modicon M340 CPU Firmware SV3.70
Schneider Electric · Modicon MC80 Firmware vers:all/*
Schneider Electric · Modicon Momentum Unity M1E Processor Firmware vers:generic/<SV2.90
Schneider Electric · Modicon Momentum Unity M1E Processor Firmware SV2.90
Schneider Electric · EcoStruxure™ Control Expert vers:generic/<16.2HF003
Schneider Electric · EcoStruxure™ Control Expert 16.2_HF003

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more