First published: Wed Feb 14 2024(Updated: )
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider Electric Modicon M340 BMXP341000 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP341000 | ||
All of | ||
Schneider Electric Modicon M340 BMXP341000H Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP341000H | ||
All of | ||
Schneider Electric Modicon M340 BMXP342000 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP342000 Firmware | ||
All of | ||
Schneider Electric Modicon M340 BMXP342010 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP342010 Firmware | ||
All of | ||
Schneider Electric Modicon M340 BMXP3420102 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP3420102 | ||
All of | ||
Schneider Electric Modicon M340 BMXP3420102CL Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP3420102CL Firmware | ||
All of | ||
Schneider Electric Modicon M340 BMXP342020 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP342020 | ||
All of | ||
Schneider Electric Modicon M340 BMXP342020H Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP342020H | ||
All of | ||
Schneider Electric Modicon M340 BMXP342030 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP342030H | ||
All of | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
All of | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP3420302CL | ||
All of | ||
Schneider Electric Modicon M340 BMXP3420302H Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP3420302H Firmware | ||
All of | ||
Schneider Electric Modicon M340 BMXP342030H Firmware | <3.60 | |
Schneider Electric Modicon M340 BMXP342030H | ||
All of | ||
Schneider Electric Modicon M580 BMEP581020 | <4.20 | |
Schneider Electric Modicon M580 BMEP581020 | ||
All of | ||
Schneider Electric Modicon M580 BMEP581020H firmware | <4.20 | |
Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 BMEP582020 Firmware | <4.20 | |
Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 Firmware | <4.20 | |
Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <4.20 | |
schneider-electric Modicon M580 | ||
All of | ||
Modicon M580 | <4.20 | |
schneider-electric Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <4.21 | |
Schneider Electric Modicon M580 BMEP582040S | ||
All of | ||
Schneider Electric Modicon M580 BMEP583020 Firmware | <4.20 | |
Schneider Electric Modicon M580 BMEP583020 | ||
All of | ||
Schneider Electric Modicon M580 BMEP583040 Firmware | <4.20 | |
Schneider Electric Modicon M580 BMEP583040 | ||
All of | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | <4.20 | |
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
All of | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | <4.20 | |
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
All of | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | <4.21 | |
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
All of | ||
schneider-electric Modicon M580 BMEP585040C Firmware | <4.20 | |
schneider-electric Modicon M580 BMEP585040C Firmware | ||
All of | ||
Schneider Electric OPC UA Module for M580 Firmware | <4.20 | |
Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 | <4.20 | |
schneider-electric modicon m580 bmep586040 firmware | ||
All of | ||
Schneider Electric Modicon M580 BMEP586040C firmware | <4.20 | |
schneider-electric Modicon M580 bmep586040c firmware | ||
All of | ||
Schneider Electric Modicon M580 BMEH582040 Firmware | <4.20 | |
schneider-electric Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 Firmware | <4.20 | |
Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 BMEH584040 Firmware | <4.20 | |
schneider-electric Modicon M580 bmeh584040c | ||
All of | ||
Schneider Electric Modicon M580 Firmware | <4.21 | |
Modicon M580 | ||
All of | ||
Modicon M580 | <4.20 | |
Schneider Electric Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 BMEH584040S Firmware | <4.21 | |
Schneider Electric Modicon M580 BMEH584040S Firmware | ||
All of | ||
Schneider Electric Modicon M580 | <4.20 | |
Schneider Electric Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 Firmware | <4.20 | |
Modicon M580 | ||
All of | ||
Schneider Electric Modicon M580 Firmware | <4.21 | |
Schneider Electric Modicon M580 | ||
All of | ||
Schneider Electric Modicon MC80 | ||
schneider-electric modicon mc80 bmkc8020301 firmware | ||
All of | ||
Modicon MC80 Firmware | ||
Modicon MC80 Firmware | ||
All of | ||
Schneider Electric Modicon MC80 | ||
Modicon MC80 Firmware | ||
All of | ||
Schneider Electric Modicon Momentum 171CBU78090 | ||
Schneider Electric Modicon Momentum 171CBU78090 | ||
All of | ||
Schneider Electric Modicon Momentum 171CBU98090 | ||
Schneider Electric Modicon Momentum 171CBU98090 | ||
All of | ||
Schneider Electric Modicon Momentum 171CBU98091 Firmware | ||
Schneider Electric Modicon Momentum 171CBU98091 Firmware | ||
EcoStruxure Control Expert | <16.0 | |
Schneider Electric EcoStruxure Process Expert | <2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6408 is considered to have a high severity due to its potential to cause denial of service and compromise the confidentiality and integrity of controllers.
To fix CVE-2023-6408, it is recommended to update the affected Schneider Electric Modicon firmware to versions higher than 3.60 or 4.20 as applicable.
CVE-2023-6408 affects several models of Schneider Electric Modicon controllers, including Modicon M340 and Modicon M580 with specific firmware versions.
Exploiting CVE-2023-6408 could allow an attacker to conduct a Man in the Middle attack, leading to loss of service and data integrity.
Currently, no official workarounds have been provided for CVE-2023-6408 other than applying the recommended firmware updates.