CVE-2013-2763

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.
References
Link Resource
http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdf Broken Link Third Party Advisory US Government Resource
http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdf Broken Link Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_noc_0401_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_noc_0401:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_noe_0100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_noe_0100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_noe_0100h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_noe_0100h:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_noe_0110_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_noe_0110:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_noe_0110h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_noe_0110h:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_nor_0200h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_nor_0200h:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_p34-2010_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_p34-2010:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmx_p34-2030_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmx_p34-2030:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp341000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp341000:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342010_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342010:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342020_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:schneider-electric:modicon_m340_bmxp342030_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:modicon_m340_bmxp342030:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:52

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdf - Broken Link, Third Party Advisory, US Government Resource () http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdf - Broken Link, Third Party Advisory, US Government Resource

07 Nov 2023, 02:15

Type Values Removed Values Added
Summary ** DISPUTED ** The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions." The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.

Information

Published : 2013-04-04 11:58

Updated : 2024-11-21 01:52


NVD link : CVE-2013-2763

Mitre link : CVE-2013-2763

CVE.ORG link : CVE-2013-2763


JSON object : View

Products Affected

schneider-electric

  • modicon_m340_bmx_p34-2010
  • modicon_m340_bmx_noe_0100_firmware
  • modicon_m340_bmx_noe_0100h_firmware
  • modicon_m340_bmx_noc_0401_firmware
  • modicon_m340_bmx_noe_0100h
  • modicon_m340_bmxp341000
  • modicon_m340_bmx_nor_0200h
  • modicon_m340_bmx_p34-2010_firmware
  • modicon_m340_bmxp341000_firmware
  • modicon_m340_bmxp342030
  • modicon_m340_bmx_noc_0401
  • modicon_m340_bmx_p34-2030
  • modicon_m340_bmx_noe_0110
  • modicon_m340_bmx_noe_0100
  • modicon_m340_bmx_noe_0110h_firmware
  • modicon_m340_bmxp342010
  • modicon_m340_bmx_noe_0110h
  • modicon_m340_bmx_noe_0110_firmware
  • modicon_m340_bmxp342020_firmware
  • modicon_m340_bmxp342030_firmware
  • modicon_m340_bmx_p34-2030_firmware
  • modicon_m340_bmxp342010_firmware
  • modicon_m340_bmxp342020
  • modicon_m340_bmx_nor_0200h_firmware
CWE
CWE-400

Uncontrolled Resource Consumption