7.5
CVSSv3

CVE-2017-6017

Published: 30/06/2017 Updated: 10/04/2024
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A Resource Exhaustion issue exists in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric bmxnoc0401_firmware 2.8

schneider-electric bmxnoe0100_firmware 2.8

schneider-electric bmxnoe0110_firmware 2.8

schneider-electric bmxnoe0110h_firmware 2.8

schneider-electric bmxnor0200h_firmware 2.8

schneider-electric modicon_m340_bmxp341000_firmware 2.8

schneider-electric modicon_m340_bmxp342000_firmware 2.8

schneider-electric modicon_m340_bmxp3420102_firmware 2.8

schneider-electric modicon_m340_bmxp3420102cl_firmware 2.8

schneider-electric modicon_m340_bmxp342020_firmware 2.8

schneider-electric modicon_m340_bmxp342020h_firmware 2.8

schneider-electric modicon_m340_bmxp342030_firmware 2.8

schneider-electric modicon_m340_bmxp3420302_firmware 2.8

schneider-electric modicon_m340_bmxp3420302h_firmware 2.8

schneider-electric modicon_m340_bmxp342030h_firmware 2.8