PT-2024-1606 · Schneider Electric · Ecostruxure Control Expert+4

Published

2024-02-13

·

Updated

2025-01-23

·

CVE-2023-6408

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Schneider Electric Modicon M340 CPU BMXP34, M580 CPU BMEP, M580 CPU BMEH, M580 CPU Safety BMEP58S, M580 CPU Safety BMEH58S versions (affected versions not specified) EcoStruxure Control Expert versions (affected versions not specified) EcoStruxure Process Expert versions (affected versions not specified)
Description The issue is related to the lack of message integrity checks during transmission in the communication channel, which could allow a remote attacker to conduct a Man in the Middle attack. This may cause a denial of service and loss of confidentiality and integrity of controllers.
Recommendations For Schneider Electric Modicon M340 CPU BMXP34, M580 CPU BMEP, M580 CPU BMEH, M580 CPU Safety BMEP58S, M580 CPU Safety BMEH58S, consider implementing additional security measures to enforce message integrity during transmission until a patch is available. For EcoStruxure Control Expert and EcoStruxure Process Expert, restrict access to the communication channel to minimize the risk of exploitation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-01202
CVE-2023-6408

Affected Products

Ecostruxure Control Expert
Ecostruxure Process Expert
M580 Cpu Bmeh
M580 Cpu Safety Bmeh58*S
Schneider Electric Modicon M340 Cpu Bmxp34