CVE-2017-6017
30.06.2017, 03:29
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | bmxnoc0401_firmware | 2.8 |
schneider-electric | bmxnoe0100_firmware | 2.8 |
schneider-electric | bmxnoe0110_firmware | 2.8 |
schneider-electric | bmxnoe0110h_firmware | 2.8 |
schneider-electric | bmxnor0200h_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp341000_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp342000_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp3420102_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp3420102cl_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp342020_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp342020h_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp342030_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp3420302_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp3420302h_firmware | 2.8 |
schneider-electric | modicon_m340_bmxp342030h_firmware | 2.8 |
𝑥
= Vulnerable software versions
References