Schneider Electric Modicon Controllers
Schneider Electric Modicon Programmable Automation Controllers contain multiple vulnerabilities in communication handling and command validation that allow remote code execution. These controllers are widely used in energy and manufacturing for networked control and display of complex processes. Failure to apply fixes may enable execution of unsolicited commands on the PLC, resulting in loss of availability, execution of unsafe operations, or corruption of control logic. The vulnerabilities stem from improper input validation (CWE-125), missing authentication (CWE-290, CWE-807), insufficient security checks (CWE-284, CWE-501), and information disclosure (CWE-200). A February 2025 update addressed additional issues in Quantum Safety processors.
- Network access to the Modicon controller (direct or routed)
- Controller exposed to a network segment accessible from the attacker
- Default or weak network segmentation allowing external communication
Patching may require device reboot — plan for process interruption
/api/v1/advisories/0984f044-41eb-41b0-8996-492f6e7b2140