Modicon M340 DoS Flaw Patched; Two Module Lines Still Open
The BMXNOE0100, BMXNOE0110, BMXNOR0200H, and M340 controller all have fixes, but the M580 Global Data module and BMXNOC0401 remain on a remediation plan with no shipped patch.
TL;DR
CISA published an advisory for CVE-2025-6625 (CVSS 7.5), an improper input validation flaw in Schneider Electric's Modicon M340 controllers and communication modules. Crafted FTP commands can trigger a denial-of-service condition that makes the device unavailable. Patches are available: SV3.60 for BMXNOE0100, SV6.80 for BMXNOE0110, SV1.7 IR27 for BMXNOR0200H, and SV3.70 for the M340 controller. Schneider Electric has not yet shipped fixes for the M580 Global Data module (BMXNGD0100) or the BMXNOC0401 X80 Ethernet communication module, both remain on a "remediation plan for all future versions" with no ship date.
CISA's advisory lands as a routine ICS-CERT publication, but the patch matrix deserves a second look. The vulnerability itself is straightforward: CWE-20 improper input validation on FTP command handling that an attacker can use to deny service on affected devices. FTP is disabled by default on these modules, which limits the exposure, but any environment where it's been turned on for operational reasons has a problem that needs a maintenance window.
Four of the six affected product lines have shipped fixes. The BMXNOE0100 Modbus/TCP module gets version 3.60; the BMXNOE0110 FactoryCast variant gets 6.80; the BMXNOR0200H Ethernet/Serial RTU module gets SV1.7 IR27; the M340 controller itself gets firmware version SV3.70. All require a device reboot to complete the firmware upgrade, that's the operational scheduling burden, not the vulnerability itself.
The two holdouts are the M580 Global Data module (BMXNGD0100) and the BMXNOC0401 X80 Ethernet communication module, both listed as affected for all versions, with Schneider Electric stating only that a "remediation plan" is being established for future versions. No fix, no timeline. Until patches ship, the advisory's mitigation language for those modules is the standard industrial-controls playbook: confirm FTP is disabled, segment the network, firewall port 21, and use VPNs for any remote access requirement.
The critical-infrastructure sectors flagged (chemical, critical manufacturing, energy, water and wastewater) mean this sits on the radar of defense-industrial-base contractors and managed service providers running Modicon hardware in operational technology environments. For the four products with fixes, the to-do is scheduling a reboot. For the two without, the to-do is verifying FTP isn't listening.
Published ·Deep Fathom