Skip to content

Security1 publisher2 min readPublished

A crafted FTP command takes Schneider's Modicon M340 and five communication modules offline

CISA's ICSA-26-260-04 gives fixed firmware for four of the six affected Schneider parts and lists the BMXNGD0100 and BMXNOC0401 as affected in every version, with a remediation plan for those still being written.

The Watch · Security desk

Illustration accompanying A crafted FTP command takes Schneider's Modicon M340 and five communication modules offline

What happened

  • CISA advisory ICSA-26-260-04 says a specific crafted FTP command triggers an improper input validation bug that causes a denial of service on Schneider Electric's Modicon M340 and its communication modules.
  • Schneider says it is still establishing a remediation plan for future versions of the BMXNGD0100 M580 Global Data module and the BMXNOC0401 X80 Ethernet module, both listed as affected in all versions.
  • The advisory puts deployment worldwide across the chemical, commercial facilities, critical manufacturing, energy, and water and wastewater sectors, with Schneider Electric headquartered in France.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A patch pass keyed to controller firmware clears one part number out of six here, and one of the five modules sits in the M580 catalogue instead of the M340 one.
  • exposure For sites running a BMXNGD0100 or a BMXNOC0401, firmware is not an option yet, so uptime on those racks depends on network controls holding until Schneider ships.
  • cost Both BMXNOE fixes complete only after a reboot, so patching a rack costs a maintenance window on a live process.
  • contradiction Schneider lists the Ethernet/serial RTU module as both fixed in SV1.7 IR27 and affected in all versions, so a compliance check run against the version table can return either answer.

The precondition is an FTP listener. Schneider says the FTP service is disabled by default, and tells customers to disable it when it is not in use [8]. The exposed population is therefore the racks where someone enabled FTP and left it enabled. Where it is on, the advisory says one specific crafted FTP command is enough to cause a denial of service, and the stated result is the unavailability of the device [2][3].

Count the affected list. Six entries. One is controller firmware, Modicon M340 below SV3.70. The other five are communication modules: the BMXNOR0200H Ethernet/serial RTU module, the BMXNGD0100 M580 Global Data module, the BMXNOC0401 X80 Ethernet/IP and Modbus TCP module, the BMXNOE0100 Modbus/TCP Ethernet module, and the BMXNOE0110 Modbus/TCP FactoryCast module [4][14]. For five of the six, the device that becomes unavailable is the Ethernet or serial path into the rack [4].

The BMXNGD0100 is catalogued as an M580 part [4], so an asset query scoped to M340 racks will miss it.

Four products have a published fixed version: BMXNOE0100 at 3.60, BMXNOE0110 at 6.80, the M340 controller at SV3.70, and the BMXNOR0200H at SV1.7 IR27 [5]. Both BMXNOE upgrades need a reboot to complete [6]. Schneider also names the M340 and the BMXNOR0200H in the group for which it is "establishing a remediation plan for all future versions", alongside the BMXNGD0100 and the BMXNOC401 [7]. Two of those four already have fix versions listed higher up the same document [5][7].

The version table disagrees with itself on the RTU module. It appears once as affected below SV1.7_IR27 and once as affected in all versions [11]. The advisory gives no CVE identifier, no CVSS score, and no word on whether the crafted FTP command needs an authenticated session [15].

For the BMXNGD0100 and the BMXNOC0401 there is no firmware yet [13]. Schneider's instruction for those is network segmentation and a firewall blocking all unauthorized access to port 21, plus VPN tunnels where remote access is required [9].

What to watch

  • An update to ICSA-26-260-04 carrying fixed firmware for the BMXNGD0100 and the BMXNOC0401.
  • A CVE identifier and CVSS score for the FTP input validation bug. Whether the FTP session needs credentials is not in the advisory.
  • Any reporting of the crafted FTP command being used against Modicon racks with port 21 reachable.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories