CVE-2020-7537: High severity schneider electric modicon m580 bmep584040 firmware vulnerability
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7537?
CVE-2020-7537 is a vulnerability in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium that could cause denial of service.
Which software versions are affected by CVE-2020-7537?
Modicon M580 Bmep584040 Firmware up to version 3.20, Modicon M580 Bmep582040 Firmware up to version 3.20, Modicon M580 Bmep586040 Firmware up to version 3.20, Modicon M580 Bmep585040 Firmware up to version 3.20, Modicon M580 Bmep582020 Firmware up to version 3.20, Modicon M580 Bmep581020 Firmware up to version 3.20, Modicon M580 Bmep584020 Firmware up to version 3.20, Modicon M580 Bmep583040 Firmware up to version 3.20, Modicon M580 Bmep583020 Firmware up to version 3.20, Bmxp341000 Firmware up to version 3.30, Bmxp342000 Firmware up to version 3.30, Bmxp3420102 Firmware up to version 3.30, Bmxp3420102cl Firmware up to version 3.30, Bmxp342020 Firmware up to version 3.30, Bmxp3420302 Firmware up to version 3.30, Bmxp3420302cl Firmware up to version 3.30, Tsxp574634 Firmware, Tsxp575634 Firmware, Tsxp576634 Firmware.
How severe is CVE-2020-7537?
CVE-2020-7537 has a severity rating of 7.5 out of 10 (high severity).
How can I fix CVE-2020-7537?
Apply the necessary security updates provided by Schneider Electric to fix CVE-2020-7537.
Where can I find more information about CVE-2020-7537?
You can find more information about CVE-2020-7537 at the following link: [SEVD-2020-343-08](https://www.se.com/ww/en/download/document/SEVD-2020-343-08/).