← Back

Modicon M580 Firmware

modicon_m580_firmware

Vendor: Schneider Electric • 41 CVEs

CVEs (41)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
8140cpu65 Firmware
Bmeh58s FirmwareBmep58s Firmware+5 more
Nov 21, 2024
Apr 19, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated...Show more
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user. Show less
1Schneider Electric
7Bmeh58s Firmware
Bmep58s FirmwareModicon M340 Firmware+4 more
Feb 5, 2025
Apr 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol.
1Schneider Electric
4Ecostruxure Control Expert
Modicon M340 FirmwareModicon M580 Firmware+1 more
Nov 21, 2024
Mar 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity...Show more
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.Show less
1Schneider Electric
29140cpu65150 Firmware
140cpu65160 Firmware140cpu65160s Firmware+26 more
May 29, 2026
Jan 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a D...Show more
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service of the controller when reading specific memory blocks using Modbus TCP.Show less
1Schneider Electric
29140cpu65150 Firmware
140cpu65160 Firmware140cpu65160s Firmware+26 more
May 29, 2026
Jan 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a D...Show more
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when writing specific physical memory blocks using Modbus TCP.Show less
1Schneider Electric
29140cpu65150 Firmware
140cpu65160 Firmware140cpu65160s Firmware+26 more
May 29, 2026
Jan 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a D...Show more
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when reading data with invalid index using Modbus TCP.Show less
1Schneider Electric
23Modicon M340 Firmware
Modicon M580 FirmwareTsxmcpc002m Firmware+20 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the c...Show more
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol.Show less
1Schneider Electric
3Modicon Bmenoc 0311 Firmware
Modicon Bmenoc 0321 FirmwareModicon M580 Firmware
Nov 21, 2024
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST...Show more
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.Show less
1Schneider Electric
3Modicon Bmenoc 0311 Firmware
Modicon Bmenoc 0321 FirmwareModicon M580 Firmware
Nov 21, 2024
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided b...Show more
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.Show less
1Schneider Electric
3Modicon Bmenoc 0311 Firmware
Modicon Bmenoc 0321 FirmwareModicon M580 Firmware
Nov 21, 2024
Oct 29, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could ca...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FT...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FTP service when upgrading the firmware with a version incompatible with the application in the controller using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when usin...Show more
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.Show less
1Schneider Electric
23Modicon M340 Firmware
Modicon M580 FirmwareTsxmcpc002m Firmware+20 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information wh...Show more
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC when upgrading the controller with a firmware package containing an invalid web server image using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmwar...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the controller with an empty firmware package using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PL...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with a missing web server image inside the package using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Nov 21, 2024
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmwar...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with no firmware image inside the package using FTP protocol.Show less
1Schneider Electric
1Modicon M580 Firmware
Nov 21, 2024
Sep 17, 2019
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
1Schneider Electric
2Modicon M340 Firmware
Modicon M580 Firmware
May 29, 2026
Sep 17, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to spec...Show more
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.Show less
1Schneider Electric
4Modicon M340 Firmware
Modicon M580 FirmwareModicon Premium Firmware+1 more
Nov 21, 2024
Sep 17, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which...Show more
A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.Show less