A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions) and Modicon M340 controller (all firmware versions), which could cause denial of service when truncated SNMP packets on port 161/UDP are received by the device.
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Link | Tags |
---|---|
https://www.schneider-electric.com/en/download/document/SEVD-2019-225-03/ | vendor advisory |
https://www.schneider-electric.com/en/download/document/SEVD-2019-225-02/ | vendor advisory |
https://security.cse.iitk.ac.in/responsible-disclosure | third party advisory |