CVE-2024-8936: Schneider Electric Modicon m340 CPU Part Numbers BMXP34*

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory.

Affected products

Published 2024-11-13. Last modified 2026-06-17.