CVE-2021-22786
—CVSS 3.1
7.5 high
EPSS
<1%p48
Published
()
Modified
Description
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP34*) (Versions prior to V3.30), Modicon M580 CPU (part numbers BMEP* and BMEH*) (Versions prior to SV3.20), Modicon MC80 (BMKC80) (Versions prior to V1.6), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions), Modicon Momentum MDI (171CBU*) (Versions prior to V2.3), Legacy Modicon Quantum (All Versions)
- Vendors
- schneider-electric
- Products
- modicon m340 bmxp341000 firmware, modicon m340 bmxp342000 firmware, modicon m340 bmxp342010 firmware, modicon m340 bmxp3420102 firmware, modicon m340 bmxp342020 firmware, modicon m340 bmxp342020h firmware, modicon m340 bmxp342030 firmware, modicon m340 bmxp3420302 firmware, modicon m340 bmxp3420302h firmware, modicon m340 bmxp342030h firmware, modicon m580 bmeh582040 firmware, modicon m580 bmeh582040c firmware
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.