{"api_version":"v1","generated_at":"2026-10-09T12:05:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-schneider-electric-modicon-m340-cpus-0cc657e29bc2","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Modicon M340 CPUs","next_cursor":null,"observations":[{"affected":"BMXP34* < V3.40; BMXNOE* All Versions; BMXNOR* < v1.7 IR24","affected_versions_present":true,"cve_id":"CVE-2022-0222","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-0222","fixed":"Version 3.50 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/BMXP34xxxxx_SV_03. 50/ If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: \u2022 Setup network segmentation and implement a firewall to block all unauthorized access to port 161/UDP. \u2022 Configure the Access Control List following the recommendations of the user manual \u201cModicon M340 for Ethernet Communications Modules and Processors User Manual\u201d in chapter \u201cMessaging Configuration Parameters\u201d: https://www.se.com/ww/en/download/document/31007131K010 00/ \u2022 Setup a VPN between the Modicon PLC impacted modules and the engineering workstation containing EcoStruxure Control Expert.","last_modified":"2025-04-29T15:24:51.881Z","patch_url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-102-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-102-02.pdf","primary_source":"","published":"2022-11-22T00:00:00.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Schneider Electric"}}
