CVE-2022-0222
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80 Ethernet Communication modules:BMXNOE0100 (H), BMXNOE0110 (H), BMXNOR0200H RTU(BMXNOE* all versions)(BMXNOR* versions prior to v1.7 IR24)
Affected (14)
Products: Schneider Electric: Modicon M340 Bmxp341000 Firmware, Modicon M340 Bmxp342000 Firmware, Modicon M340 Bmxp342010 Firmware, Modicon M340 Bmxp3420102 Firmware, Modicon M340 Bmxp342020 Firmware, Modicon M340 Bmxp342020h Firmware, Modicon M340 Bmxp342030 Firmware, Modicon M340 Bmxp3420302 Firmware, Modicon M340 Bmxp3420302h Firmware, Modicon M340 Bmxp342030h Firmware, Modicon M340 Bmxnoe0100 Firmware, Modicon M340 Bmxnoe0110 Firmware, Modicon M340 Bmxnoe0110h Firmware, Modicon M340 Bmxnor0200h Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp341000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp342000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp342010 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp3420102 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp342020 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp342020h | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp342030 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp3420302 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp3420302h | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.50 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxp342030h | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxnoe0100 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxnoe0110 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxnoe0110h | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Modicon M340 Bmxnor0200h | All versions |
References (2)
Source: cybersecurity@se.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.