Schneider Electric Update
3542Warning Date
Severity Level
Warning Number
Target Sector
19 January, 2020
● High
2020-813
Energy - Manufacturing - Commercial Facilities
Description:
Schneider Electric has released security update to address multiple vulnerabilities in the following products:
- Modicon M580, all versions prior to v2.80
- Modicon M340, all versions prior to v3.01
- Modicon Premium, all versions prior to v3.20
- Modicon Quantum, all versions prior to v3.60
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS). In either cases:
- Reading specific memory blocks using Modbus TCP.
- Writing specific physical memory blocks using Modbus TCP.
- Reading data with invalid index using Modbus TCP.
Best practice and Recommendations:
The CERT team encourages users to review Schneider Electric security advisory and apply the necessary updates:
https://www.se.com/ww/en/download/document/SEVD-2019-344-01/