PT-2022-3762 · Schneider Electric · Modicon M340 Cpu+4

CVE-2022-0222

·

Published

2022-04-12

·

Updated

2022-11-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Modicon M340 CPUs versions prior to V3.40 Modicon M340 X80 Ethernet Communication modules: BMXNOE0100 (H), BMXNOE0110 (H) BMXNOE* all versions BMXNOR* versions prior to v1.7 IR24
Description A vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. This issue is related to improper privilege management. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service by sending specially crafted requests.
Recommendations For Modicon M340 CPUs versions prior to V3.40, update to version V3.40 or later to resolve the issue. For BMXNOE* all versions, consider disabling SNMP access until a patch is available. For BMXNOR* versions prior to v1.7 IR24, update to version v1.7 IR24 or later to resolve the issue. As a temporary workaround, consider restricting access to the SNMP service to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04552
CVE-2022-0222

Affected Products

Bmxnoe
Bmxnoe0100
Bmxnoe0110
Bmxnor
Modicon M340 Cpu