CVE-2024-8938: Schneider Electric Modicon m340
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call to tamper with memory area involved in memory size computation.
Affected products
- Schneider Electric Modicon m340
- Schneider Electric Modicon MC80: any version
- Schneider Electric Modicon Momentum Unity m1e Processor: any version
- Schneider Electric Modicon m340 CPU Part Numbers BMXP34*
- Schneider Electric Modicon MC80 Part Numbers BMKC80: any version
- Schneider Electric Modicon Momentum Unity m1e Processor 171cbu*: any version
Published 2024-11-13. Last modified 2026-06-17.