HIGH · 7.5

CVE-2017-6017

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP...

Vulnerability Description

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Schneider-ElectricBmxnoc0401 Firmware2.8
Schneider-ElectricBmxnoc0401-
Schneider-ElectricBmxnoe0100 Firmware2.8
Schneider-ElectricBmxnoe0100-
Schneider-ElectricBmxnoe0110 Firmware2.8
Schneider-ElectricBmxnoe0110-
Schneider-ElectricBmxnoe0110H Firmware2.8
Schneider-ElectricBmxnoe0110H-
Schneider-ElectricBmxnor0200H Firmware2.8
Schneider-ElectricBmxnor0200H-
Schneider-ElectricModicon M340 Bmxp341000 Firmware2.8
Schneider-ElectricModicon M340 Bmxp341000-
Schneider-ElectricModicon M340 Bmxp342000 Firmware2.8
Schneider-ElectricModicon M340 Bmxp342000-
Schneider-ElectricModicon M340 Bmxp3420102 Firmware2.8
Schneider-ElectricModicon M340 Bmxp3420102-
Schneider-ElectricModicon M340 Bmxp3420102Cl Firmware2.8
Schneider-ElectricModicon M340 Bmxp3420102Cl-
Schneider-ElectricModicon M340 Bmxp342020 Firmware2.8
Schneider-ElectricModicon M340 Bmxp342020-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-6017?

CVE-2017-6017 is a vulnerability with a CVSS score of 7.5 (HIGH). A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP...

How severe is CVE-2017-6017?

CVE-2017-6017 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-6017?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Bmxnoc0401 Firmware, Schneider-Electric Bmxnoc0401, Schneider-Electric Bmxnoe0100 Firmware, Schneider-Electric Bmxnoe0100, Schneider-Electric Bmxnoe0110 Firmware.