Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Multiple Schneider Electric Modicon PLC Modules Directory Traversal

Critical

Synopsis

A Schneider Electric Modicon programmable logic controller (PLC) communications module containing a directory traversal vulnerability has been detected.

Description

Schneider Electric Ethernet modules for Modicon M340, Modicon Quantum, and Modicon Premium PLCs in addition to Modicon Momentum, Modicon TSX Micro, and Modicon STB modules that provide HTTP services contain a directory traversal vulnerability. Attackers can remotely bypass web server authentication thereby achieving unauthenticated administrative access and control of the device.

Solution

See Schneider Electric's Security Advisory, SEVD-2014-260-01, for a list of firmware updates that fix this issue.