news.mlab.sh
Back to the feed
vulnerability

Schneider Electric Modicon M340 Controller and Communication Modules

HighCVSS 7.5
Summary

Schneider Electric has identified and released fixes for a vulnerability in its Modicon M340 Controller and Communication Modules. Specifically, a CWE-20 Improper Input Validation vulnerability could lead to a Denial of Service attack when a specific FTP command is sent to the device. Several firmware versions are affected, and the vendor recommends disabling FTP services and implementing network segmentation and firewalls to mitigate the risk. This vulnerability could impact critical infrastructure sectors, including chemical, commercial facilities, and manufacturing.

Schneider Electric is aware of a vulnerability in its Modicon M340 Controller and Communication Modules. The vulnerability, identified as CWE-20 Improper Input Validation, could cause a Denial of Service attack when a specific FTP command is sent to the device. This affects several versions of the Modicon M340, including:

  • Schneider Electric Ethernet/Serial RTU Module: versions generic/<SV1.7_IR27
  • Schneider Electric M580 Global Data module: all/*
  • Schneider Electric Ethernet / Serial RTU Module: all/*
  • Schneider Electric Modbus/TCP Ethernet Modicon M340 module: versions prior to 3.60
  • Schneider Electric Modbus/TCP Ethernet Modicon M340 FactoryCast module: versions prior to 6.80

These modules are used in a variety of critical infrastructure sectors, including chemical, commercial facilities, critical manufacturing, energy, and water and wastewater treatment.

The vulnerability stems from improper input validation, allowing a crafted FTP command to trigger a denial of service.

Schneider Electric has released firmware updates to address this issue. The following links provide access to the updates:

  • Version 3.60 of BMXNOE0100: https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card/
  • Version 6.80 of BMXNOE110: https://www.se.com/ww/en/product/BMXNOE110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/
  • Version SV3.70 of Modicon M340: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
  • Version SV1.7 IR27 of BMXNOR0200H: https://www.se.com/ww/en/product/BMXNOR0200H/ethernet-serial-rtu-module-2-x-rj45/

To mitigate the risk, Schneider Electric recommends the following:

  • Disable FTP service by default.
  • Ensure FTP service is disabled when not in use.
  • Implement network segmentation and deploy a firewall to block unauthorized access to ports 21/FTP.
  • Use VPN (Virtual Private Networks) tunnels if remote access is required.

Schneider Electric is establishing a remediation plan for all future versions of Modicon M340, BMXNOR0200H, BMXNGD0100, and BMXNOC401. Until these updates are available, the above mitigations are recommended.

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities, including minimizing network exposure for control system devices, locating control systems networks behind firewalls, and using more secure remote access methods like VPNs.

This advisory is a verbatim republication of Schneider Electric CPCERT SEVD-2025-224-05 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided “as-is” for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory.

Read the full article at CISA Advisories