<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>BMXNOE0110 (&lt; 6.80) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/bmxnoe0110--6.80/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 17:11:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/bmxnoe0110--6.80/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Input Validation in Schneider Electric Modicon M340 Modules</title><link>https://feed.craftedsignal.io/briefs/2026-09-modicon-m340-dos/</link><pubDate>Thu, 17 Sep 2026 17:11:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-modicon-m340-dos/</guid><description>An improper input validation vulnerability (CVE-2025-6625) in Schneider Electric Modicon M340 controllers and communication modules allows unauthenticated attackers to cause a denial-of-service via crafted FTP commands.</description><content:encoded><![CDATA[<p>Schneider Electric has disclosed a vulnerability (CVE-2025-6625) affecting multiple Modicon M340 controller and communication modules. The flaw stems from improper input validation in the device's FTP service, which is susceptible to denial-of-service (DoS) attacks. An unauthenticated remote attacker can send a specially crafted FTP command to an affected device, causing it to crash or become unresponsive, leading to operational unavailability.</p>
<p>The vulnerability impacts a wide range of modules, including the BMXNOR0200H, BMXNGD0100, BMXNOC0401, BMXNOE0100, and BMXNOE0110, as well as the core M340 controller firmware. Given the deployment of these devices in critical infrastructure sectors like energy, water and wastewater, and manufacturing, the impact of service disruption is significant. Schneider Electric has released firmware updates for several modules and recommends disabling FTP services or implementing strict network segmentation if patching is not immediately feasible.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a Denial of Service (DoS), rendering the affected industrial controller unavailable. This poses a high risk to critical infrastructure sectors - including energy, water, wastewater, and chemical manufacturing - where device uptime is essential for safe operations. There are no reports of remote code execution or data exfiltration associated with this specific vulnerability.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the vendor-provided firmware updates immediately to affected modules:</li>
<li>Update BMXNOE0100 to version 3.60 or later.</li>
<li>Update BMXNOE0110 to version 6.80 or later.</li>
<li>Update Modicon M340 controller firmware to version SV3.70 or later.</li>
<li>Update BMXNOR0200H to version SV1.7 IR27 or later.</li>
<li>Disable the FTP service on all Modicon M340 modules if it is not required for operational tasks.</li>
<li>Implement strict network segmentation and firewall rules to block unauthorized access to TCP port 21 on all industrial devices.</li>
<li>Require the use of VPNs for any necessary remote maintenance or monitoring access to the control network.</li>
<li>Ensure controllers are kept in locked cabinets and are not left in &quot;Program&quot; mode during standard operation.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>ics</category><category>cve-2025-6625</category><category>denial-of-service</category><category>schneider-electric</category></item></channel></rss>