Schneider Electric Modicon M340, BMXNOE0100, and BMXNOE0110 (Update A)
Risk Summary
Schneider Electric is aware of a vulnerability in its Modicon M340 and BMXNOE0100 and BMXNOE0110 products. The Modicon M340 is a programmable automation controller; BMXNOE0100 and BMXNOE0110 are network modules used with Modicon M340. Failure to apply the mitigations provided below may prevent user to update the device firmware and prevent proper behavior of the webserver. The BMXNOE and Modicon M340 operations are not impacted by this vulnerability. August Update: Remediations are available for BMXNOE0100 (Modbus/TCP Ethernet Modicon M340 module) and BMXNOE0110 (Modbus/TCP Ethernet Modicon M340 FactoryCast module)
CVEs (1)
Remediations
- Version SV3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card
- Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
- Version SV6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/
- If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to FTP port 21/TCP on the devices. • FTP service is disabled by default. Deactivate the FTP service after use when not needed. • Configure the Access Control List following the recommendations of the user manuals: o “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31 007131K01000/
Affected Vendors
Affected Products (6)
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more