← Back

CVE-2022-34765

nvd nist
Published: Jul 13, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

Affected (2)

Opc Ua Module For M580 Firmware
X80 Advanced Rtu Module Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.10
Running on/withPlatform Versions
Schneider Electric
Opc Ua Module For M580
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 2.01
Running on/withPlatform Versions
Schneider Electric
X80 Advanced Rtu Module
All versions

Timeline

No history available yet.