SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-2763

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors.

MEDIUM 5.0EPSS 2.13%

Does this matter?

Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.

Description

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
2.13% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
schneider-electric/modicon m340 bmx noc 0401 firmware · schneider-electric/modicon m340 bmx noe 0100 firmware · schneider-electric/modicon m340 bmx noe 0100h firmware · schneider-electric/modicon m340 bmx noe 0110 firmware · schneider-electric/modicon m340 bmx noe 0110h firmware · schneider-electric/modicon m340 bmx nor 0200h firmware · schneider-electric/modicon m340 bmx p34-2010 firmware · schneider-electric/modicon m340 bmx p34-2030 firmware · schneider-electric/modicon m340 bmxp341000 firmware · schneider-electric/modicon m340 bmxp342010 firmware · schneider-electric/modicon m340 bmxp342020 firmware · schneider-electric/modicon m340 bmxp342030 firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.