← Back

CVE-2021-22749

nvd nist
Published: Jun 11, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module.

Affected (7)

Configuration A
7 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version sv1.6 ir4
Version sv1.7 ir10
Version sv1.7 ir15b
Version sv1.7 ir17
Version sv1.7 ir18
Version sv1.7 ir19
Version sv1.7 ir20
Running on/withPlatform Versions
Schneider Electric
Modicon X80 Bmxnor0200h Rtu
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.