CERT-In Advisory
CIAD-2024-0010
Multiple Vulnerabilities in Schneider Electric Products
Original Issue Date: February 19, 2024
Severity Rating: High
Software Affected
- Modicon M340 CPU (part numbers BMXP34*)
- Modicon M580 CPU (part numbers BMEP* and BMEH*,excluding M580 CPU Safety)
- Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)
- EcoStruxureż Control Expert
- EcoStruxureż Process Expert
Overview
Multiple vulnerabilities have been reported in Schneider Electric Products which could allow an attacker to cause denial of Service (DoS) condition, perform unauthorized access, and disclose sensitive information on the targeted system.
Description
Multiple vulnerabilities have been reported in various Schneider Electric Products:

Solution
Apply appropriate security updates as mentioned in:
https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
Vendor Information
Schneider Electric
https://www.se.com/ww/en/
References
Schneider Electric
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-01.pdf
CVE Name
CVE-2023-27975
CVE-2023-6408
CVE-2023-6409
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|