Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Denial‑of‑Service Vulnerability Discovered in Schneider Electric Modicon M340 PLC Controllers

CISA has warned that Schneider Electric’s Modicon M340 PLCs and associated communication modules contain a firmware flaw that can be remotely triggered to cause denial‑of‑service. Organizations must patch promptly to maintain audit‑ready evidence of vulnerability management.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

Schneider Electric Modicon M340 Controllers Vulnerable to Denial‑of‑Service Exploits

What Happened – CISA issued an advisory (ICSA‑26‑260‑04) reporting a flaw in Schneider Electric’s Modicon M340 PLC controller and several Ethernet/Serial communication modules. The vulnerability can be triggered remotely to cause a denial‑of‑service condition, rendering the devices unavailable until they are rebooted or the firmware is patched.

Why It Matters for Trust & Control Assurance

  • The scenario tests the vulnerability‑management control objective: maintaining up‑to‑date firmware and applying security patches to industrial‑control assets.
  • Continuous control‑assurance programs rely on documented patch‑deployment evidence to demonstrate due diligence to auditors and regulators.
  • Verisq’s Control Mapping capability can automatically map this patch‑requirement to the relevant control objectives across frameworks and capture the remediation evidence in a Trust Center repository.

Who Is Affected – Manufacturers, energy and utilities operators, and any organization that deploys Schneider Electric Modicon M340 controllers in production environments.

Recommended Actions

  • Verify firmware versions on all Modicon M340 controllers and the listed communication modules against the advisory.
  • Apply the Schneider‑provided fix immediately; document the patch rollout in your change‑management system.
  • Update your vulnerability‑management inventory and schedule regular scans for similar PLC firmware gaps.

Technical Notes – The advisory does not assign a CVE number but describes a firmware flaw that can be triggered via malformed network traffic to the Ethernet modules, leading to a DoS. No data exfiltration is indicated. Source: CISA Advisory

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →