ZeroHour

CVE-2021-22785

CVSS 3.1
7.5 high
EPSS
<1%p60
Published
()
Modified
Description

A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions)

Vendors
schneider-electric
Products
modicon m340 bmxp342020 firmware, bmxnoe0100 firmware, bmxnoe0110 firmware, bmxnoc0401 firmware, bmxnor0200h rtu firmware, tsxp574634 firmware, tsxp575634 firmware, tsxp576634 firmware, 140cpu65150 firmware, 140noe771x1 firmware, 140noc78x00 firmware, 140noc77101 firmware
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.