CVE-2024-8937: Schneider Electric Modicon m340 CPU Part Numbers BMXP34*
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in the authentication process.
Affected products
- Schneider Electric Modicon m340 CPU Part Numbers BMXP34*
- Schneider Electric Modicon MC80 Part Numbers BMKC80: any version
- Schneider Electric Modicon Momentum Unity m1e Processor 171cbu*: any version
Published 2024-11-13. Last modified 2026-06-17.