CVE & CISA-KEV Catalog

CVE-2023-6408

HIGH
8.1
CVSS v3
NVD

Description

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.

How to fix

Remediation Available
ecostruxure control expertNVD
Affected:< 16.0Fixed in:16.0CVE-2023-6408derived from NVD
ecostruxure process expertNVD
Affected:< 2023Fixed in:2023CVE-2023-6408derived from NVD
modicon m340 bmxp341000 firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp341000h firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp342000 firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp3420102 firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp3420102cl firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp342010 firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp342020 firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp342020h firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp3420302 firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp3420302cl firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp3420302h firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp342030 firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m340 bmxp342030h firmwareNVD
Affected:< 3.60Fixed in:3.60CVE-2023-6408derived from NVD
modicon m580 bmeh582040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmeh582040c firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmeh582040s firmwareNVD
Affected:< 4.21Fixed in:4.21CVE-2023-6408derived from NVD
modicon m580 bmeh584040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmeh584040c firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmeh584040s firmwareNVD
Affected:< 4.21Fixed in:4.21CVE-2023-6408derived from NVD
modicon m580 bmeh586040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmeh586040c firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmeh586040s firmwareNVD
Affected:< 4.21Fixed in:4.21CVE-2023-6408derived from NVD
modicon m580 bmep581020 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep581020h firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep582020 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep582020h firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep582040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep582040h firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep582040s firmwareNVD
Affected:< 4.21Fixed in:4.21CVE-2023-6408derived from NVD
modicon m580 bmep583020 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep583040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep584020 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep584040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep584040s firmwareNVD
Affected:< 4.21Fixed in:4.21CVE-2023-6408derived from NVD
modicon m580 bmep585040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep585040c firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep586040 firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD
modicon m580 bmep586040c firmwareNVD
Affected:< 4.20Fixed in:4.20CVE-2023-6408derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Intelligence

0.31%probability of exploitation in 30 days
23rdpercentile

Low risk: more likely to be exploited than 23% of all known CVEs.

References

Embed a live status badge for CVE-2023-6408
CVE-2023-6408 severity badge

Markdown

[![CVE-2023-6408](https://tridentstack.com/cve/badge/CVE-2023-6408.svg)](https://tridentstack.com/cve/CVE-2023-6408)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-6408"><img src="https://tridentstack.com/cve/badge/CVE-2023-6408.svg" alt="CVE-2023-6408"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-01-23.