CVE-2023-6408

HIGH
Published Feb 14, 2024 Modified Jan 23, 2025 CWE-924

Description

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.

CVSS v3.1 Score

8.1
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-924 CWE-924

Affected Products

Vendor Product
schneider-electric modicon_m340_bmxp341000_firmware
schneider-electric modicon_m340_bmxp341000
schneider-electric modicon_m340_bmxp341000h_firmware
schneider-electric modicon_m340_bmxp341000h
schneider-electric modicon_m340_bmxp342000_firmware
schneider-electric modicon_m340_bmxp342000
schneider-electric modicon_m340_bmxp342010_firmware
schneider-electric modicon_m340_bmxp342010
schneider-electric modicon_m340_bmxp3420102_firmware
schneider-electric modicon_m340_bmxp3420102
schneider-electric modicon_m340_bmxp3420102cl_firmware
schneider-electric modicon_m340_bmxp3420102cl
schneider-electric modicon_m340_bmxp342020_firmware
schneider-electric modicon_m340_bmxp342020
schneider-electric modicon_m340_bmxp342020h_firmware
schneider-electric modicon_m340_bmxp342020h
schneider-electric modicon_m340_bmxp342030_firmware
schneider-electric modicon_m340_bmxp342030
schneider-electric modicon_m340_bmxp3420302_firmware
schneider-electric modicon_m340_bmxp3420302
schneider-electric modicon_m340_bmxp3420302cl_firmware
schneider-electric modicon_m340_bmxp3420302cl
schneider-electric modicon_m340_bmxp3420302h_firmware
schneider-electric modicon_m340_bmxp3420302h
schneider-electric modicon_m340_bmxp342030h_firmware
schneider-electric modicon_m340_bmxp342030h
schneider-electric modicon_m580_bmep581020_firmware
schneider-electric modicon_m580_bmep581020
schneider-electric modicon_m580_bmep581020h_firmware
schneider-electric modicon_m580_bmep581020h
schneider-electric modicon_m580_bmep582020_firmware
schneider-electric modicon_m580_bmep582020
schneider-electric modicon_m580_bmep582020h_firmware
schneider-electric modicon_m580_bmep582020h
schneider-electric modicon_m580_bmep582040_firmware
schneider-electric modicon_m580_bmep582040
schneider-electric modicon_m580_bmep582040h_firmware
schneider-electric modicon_m580_bmep582040h
schneider-electric modicon_m580_bmep582040s_firmware
schneider-electric modicon_m580_bmep582040s
schneider-electric modicon_m580_bmep583020_firmware
schneider-electric modicon_m580_bmep583020
schneider-electric modicon_m580_bmep583040_firmware
schneider-electric modicon_m580_bmep583040
schneider-electric modicon_m580_bmep584040_firmware
schneider-electric modicon_m580_bmep584040
schneider-electric modicon_m580_bmep584020_firmware
schneider-electric modicon_m580_bmep584020
schneider-electric modicon_m580_bmep584040s_firmware
schneider-electric modicon_m580_bmep584040s
schneider-electric modicon_m580_bmep585040_firmware
schneider-electric modicon_m580_bmep585040
schneider-electric modicon_m580_bmep585040c_firmware
schneider-electric modicon_m580_bmep585040c
schneider-electric modicon_m580_bmep586040_firmware
schneider-electric modicon_m580_bmep586040
schneider-electric modicon_m580_bmep586040c_firmware
schneider-electric modicon_m580_bmep586040c
schneider-electric modicon_m580_bmeh582040_firmware
schneider-electric modicon_m580_bmeh582040
schneider-electric modicon_m580_bmeh582040c_firmware
schneider-electric modicon_m580_bmeh582040c
schneider-electric modicon_m580_bmeh584040_firmware
schneider-electric modicon_m580_bmeh584040
schneider-electric modicon_m580_bmeh582040s_firmware
schneider-electric modicon_m580_bmeh582040s
schneider-electric modicon_m580_bmeh584040c_firmware
schneider-electric modicon_m580_bmeh584040c
schneider-electric modicon_m580_bmeh584040s_firmware
schneider-electric modicon_m580_bmeh584040s
schneider-electric modicon_m580_bmeh586040_firmware
schneider-electric modicon_m580_bmeh586040
schneider-electric modicon_m580_bmeh586040c_firmware
schneider-electric modicon_m580_bmeh586040c
schneider-electric modicon_m580_bmeh586040s_firmware
schneider-electric modicon_m580_bmeh586040s
schneider-electric modicon_mc80_bmkc8020301_firmware
schneider-electric modicon_mc80_bmkc8020301
schneider-electric modicon_mc80_bmkc8020310_firmware
schneider-electric modicon_mc80_bmkc8020310
schneider-electric modicon_mc80_bmkc8030311
schneider-electric modicon_mc80_bmkc8030311_firmware
schneider-electric modicon_momentum_171cbu78090_firmware
schneider-electric modicon_momentum_171cbu78090
schneider-electric modicon_momentum_171cbu98090_firmware
schneider-electric modicon_momentum_171cbu98090
schneider-electric modicon_momentum_171cbu98091_firmware
schneider-electric modicon_momentum_171cbu98091
schneider-electric ecostruxure_control_expert
schneider-electric ecostruxure_process_expert

References

Frequently Asked Questions

What is CVE-2023-6408? +
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack. It has a CVSS v3.1 base score of 8.1 (HIGH).
How severe is CVE-2023-6408? +
CVE-2023-6408 has a CVSS v3.1 score of 8.1 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2023-6408? +
CVE-2023-6408 affects products from schneider-electric, specifically: ecostruxure_control_expert, ecostruxure_process_expert, modicon_m340_bmxp341000, modicon_m340_bmxp341000_firmware, modicon_m340_bmxp341000h, modicon_m340_bmxp341000h_firmware, modicon_m340_bmxp342000, modicon_m340_bmxp342000_firmware, modicon_m340_bmxp342010, modicon_m340_bmxp3420102, modicon_m340_bmxp3420102_firmware, modicon_m340_bmxp3420102cl, modicon_m340_bmxp3420102cl_firmware, modicon_m340_bmxp342010_firmware, modicon_m340_bmxp342020, modicon_m340_bmxp342020_firmware, modicon_m340_bmxp342020h, modicon_m340_bmxp342020h_firmware, modicon_m340_bmxp342030, modicon_m340_bmxp3420302, modicon_m340_bmxp3420302_firmware, modicon_m340_bmxp3420302cl, modicon_m340_bmxp3420302cl_firmware, modicon_m340_bmxp3420302h, modicon_m340_bmxp3420302h_firmware, modicon_m340_bmxp342030_firmware, modicon_m340_bmxp342030h, modicon_m340_bmxp342030h_firmware, modicon_m580_bmeh582040, modicon_m580_bmeh582040_firmware, modicon_m580_bmeh582040c, modicon_m580_bmeh582040c_firmware, modicon_m580_bmeh582040s, modicon_m580_bmeh582040s_firmware, modicon_m580_bmeh584040, modicon_m580_bmeh584040_firmware, modicon_m580_bmeh584040c, modicon_m580_bmeh584040c_firmware, modicon_m580_bmeh584040s, modicon_m580_bmeh584040s_firmware, modicon_m580_bmeh586040, modicon_m580_bmeh586040_firmware, modicon_m580_bmeh586040c, modicon_m580_bmeh586040c_firmware, modicon_m580_bmeh586040s, modicon_m580_bmeh586040s_firmware, modicon_m580_bmep581020, modicon_m580_bmep581020_firmware, modicon_m580_bmep581020h, modicon_m580_bmep581020h_firmware, modicon_m580_bmep582020, modicon_m580_bmep582020_firmware, modicon_m580_bmep582020h, modicon_m580_bmep582020h_firmware, modicon_m580_bmep582040, modicon_m580_bmep582040_firmware, modicon_m580_bmep582040h, modicon_m580_bmep582040h_firmware, modicon_m580_bmep582040s, modicon_m580_bmep582040s_firmware, modicon_m580_bmep583020, modicon_m580_bmep583020_firmware, modicon_m580_bmep583040, modicon_m580_bmep583040_firmware, modicon_m580_bmep584020, modicon_m580_bmep584020_firmware, modicon_m580_bmep584040, modicon_m580_bmep584040_firmware, modicon_m580_bmep584040s, modicon_m580_bmep584040s_firmware, modicon_m580_bmep585040, modicon_m580_bmep585040_firmware, modicon_m580_bmep585040c, modicon_m580_bmep585040c_firmware, modicon_m580_bmep586040, modicon_m580_bmep586040_firmware, modicon_m580_bmep586040c, modicon_m580_bmep586040c_firmware, modicon_mc80_bmkc8020301, modicon_mc80_bmkc8020301_firmware, modicon_mc80_bmkc8020310, modicon_mc80_bmkc8020310_firmware, modicon_mc80_bmkc8030311, modicon_mc80_bmkc8030311_firmware, modicon_momentum_171cbu78090, modicon_momentum_171cbu78090_firmware, modicon_momentum_171cbu98090, modicon_momentum_171cbu98090_firmware, modicon_momentum_171cbu98091, modicon_momentum_171cbu98091_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-6408? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2023-6408 — free, no signup required.

Start Free Scan