CVE-2023-6408: High severity schneider electric modicon m340 bmxp341000 firmware vulnerability
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6408?
CVE-2023-6408 is considered to have a high severity due to its potential to cause denial of service and compromise the confidentiality and integrity of controllers.
How do I fix CVE-2023-6408?
To fix CVE-2023-6408, it is recommended to update the affected Schneider Electric Modicon firmware to versions higher than 3.60 or 4.20 as applicable.
What types of devices are affected by CVE-2023-6408?
CVE-2023-6408 affects several models of Schneider Electric Modicon controllers, including Modicon M340 and Modicon M580 with specific firmware versions.
What could happen if CVE-2023-6408 is exploited?
Exploiting CVE-2023-6408 could allow an attacker to conduct a Man in the Middle attack, leading to loss of service and data integrity.
Is there a workaround for CVE-2023-6408?
Currently, no official workarounds have been provided for CVE-2023-6408 other than applying the recommended firmware updates.