CVE-2024-8936: Schneider Electric Modicon m340 CPU Part Numbers BMXP34*
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.
Affected products
- Schneider Electric Modicon m340 CPU Part Numbers BMXP34*
Published 2024-11-13. Last modified 2026-06-17.