CVE-2017-6017
published 2017-06-30CVE-2017-6017: A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.81%
90.9th percentile
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | bmxnoc0401_firmware | — | — |
| schneider-electric | bmxnoe0100_firmware | — | — |
| schneider-electric | bmxnoe0110_firmware | — | — |
| schneider-electric | bmxnoe0110h_firmware | — | — |
| schneider-electric | bmxnor0200h_firmware | — | — |
| schneider-electric | modicon_m340_bmxp341000_firmware | — | — |
| schneider-electric | modicon_m340_bmxp342000_firmware | — | — |
| schneider-electric | modicon_m340_bmxp3420102_firmware | — | — |
| schneider-electric | modicon_m340_bmxp3420102cl_firmware | — | — |
| schneider-electric | modicon_m340_bmxp342020_firmware | — | — |
| schneider-electric | modicon_m340_bmxp342020h_firmware | — | — |
| schneider-electric | modicon_m340_bmxp3420302_firmware | — | — |
| schneider-electric | modicon_m340_bmxp3420302h_firmware | — | — |
| schneider-electric | modicon_m340_bmxp342030_firmware | — | — |
| schneider-electric | modicon_m340_bmxp342030h_firmware | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4v7w-jq2v-52pw: A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP34
ghsa_unreviewed·2022-05-14
CVE-2017-6017 [HIGH] CWE-400 GHSA-4v7w-jq2v-52pw: A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP34
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.
CISA ICS
Schneider Electric Modicon M340 PLC (Update A)
cisa_ics·2017-02-23·CVSS 7.5
[HIGH] Schneider Electric Modicon M340 PLC (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Modicon M340 PLC (Update A)
Last RevisedJanuary 10, 2019
Alert CodeICSA-17-054-03
## 1. EXECUTIVE SUMMARY
-
CVSS v3 7.5
- ATTENTION: Remotely exploitable/low-skill level to exploit
- Vendor: Schneider Electric
- Equipment: Modicon M340 PLC
- Vulnerability: Resource Exhaustion
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-17-054-03 Schneider Electric Modicon M340 PLC that was published February 23, 2017, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/96414https://ics-cert.us-cert.gov/advisories/ICSA-17-054-03https://www.schneider-electric.com/en/download/document/SEVD-2017-048-02/http://www.securityfocus.com/bid/96414https://ics-cert.us-cert.gov/advisories/ICSA-17-054-03https://www.schneider-electric.com/en/download/document/SEVD-2017-048-02/
2017-06-30
Published