The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdf | us government resource third party advisory broken link |