← Back to home
ICSA-25-238-03  ·  Published 2026-06-04  ·  View on CISA ICS-CERT ↗

Schneider Electric Modicon M340 Controller and Communication Modules (Update A)

CVSS 7.5 HIGH

Risk Summary

Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se.com/us/en/product/BMXNOC0401/network-module-modicon-m340-ethernet-ip-and-modbus-tcp-4-x-rj45/?pageType=product&sourceId=BMXNOC0401: Modicon M340 X80 Ethernet Communication modules, BMXNOE0100 https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/?pageType=product&sourceId=BMXNOE0100: Modbus/TCP Ethernet Modicon M340 module, BMXNOE0110 https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/: Modbus/TCP Ethernet Modicon M340 FactoryCast module product(s). Failure to apply the fix provided below may risk Denial Of Service attack, which could result in the unavailability of the devices.

CVEs (1)

Remediations

  • Version 3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0100/networkmodule-modicon-m340-modbus-tcp-1-x-rj45-flash-memorycard/ Reboot is needed to complete the firmware upgrade
  • Version 6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0110/ethernettcp-ip-network-module-modicon-m340-automation-platformflash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/ Reboot is needed to complete the firmware upgrade
  • Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
  • If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • FTP service is disabled by default • Ensure to disable FTP service when not in use • Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP • Use VPN (Virtual Private Networks) tunnels if remote access is required
  • Schneider Electric is establishing a remediation plan for all future versions of • Modicon M340 • BMXNOR0200H • BMXNGD0100 • BMXNOC401 We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • FTP service is disabled by default • Ensure to disable FTP service when not in use • Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP • Use VPN (Virtual Private Networks) tunnels if remote access is required

Affected Vendors

Schneider Electric

Affected Products (9)

Schneider Electric · Modicon M340 Firmware vers:generic/<SV3.70
Schneider Electric · Modicon M340 Firmware SV3.70
Schneider Electric · Ethernet / Serial RTU Module vers:all/*
Schneider Electric · M580 Global Data module vers:all/*
Schneider Electric · Modicon M340 X80 Ethernet Communication modules vers:all/*
Schneider Electric · Modbus/TCP Ethernet Modicon M340 module vers:intdot/<3.60
Schneider Electric · Modbus/TCP Ethernet Modicon M340 module 3.60
Schneider Electric · Modbus/TCP Ethernet Modicon M340 FactoryCast module vers:intdot/<6.80
Schneider Electric · Modbus/TCP Ethernet Modicon M340 FactoryCast module 6.80

Affected Sectors

Critical Manufacturing, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more