EcoStruxure Control Expert and Modicon M340, M580 Security Notification
This document details multiple vulnerabilities in Schneider Electric's EcoStruxure Control Expert, Process Expert, and Modicon M340, M580, and M580 CPU Safety products, including a high-severity authentication bypass via capture-replay (CVE-2022-45789) that could allow unauthorized Modbus functions. It provides firmware remediation versions (SV4.20 for M580, SV4.21 for M580 CPU Safety) and mitigations such as VPN setup, network segmentation, and application passwords for affected products.
Failed to load PDF
Download insteadYou might also like
PowerChute Network Shutdown Communication Process Application Note
4 pages
InfraStruXure Central Server v5.x Network Application Note
5 pages
DC COMMS Upgrade Kit for DC 2100H Energy Controller Installation Guide
2 pages
STP200 Immersion Pipe Temperature Sensor Datasheet
2 pages
EcoStruxure Building Operation WebStation Overview
5 pages
APC Basic Rack PDU AP6009A Specifications
16 pages
Fault Arcs on Busbar Sets and Switchboards Technical Paper
11 pages
Modicon M241 and M251 Logic Controllers Compatibility Notice
14 pages
Okken Intelligent Low-Voltage Switchboard for Water and Wastewater Brochure
2 pages
ARGUS High-Frequency Presence Detector for High Bay Data Sheet
1 pages