60
CVE-2022-45789
—CVSS 3.1
9.8 critical
EPSS
1%p72
Published
()
Modified
Description
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions)
- Vendors
- schneider-electric
- Products
- ecostruxure control expert, ecostruxure process expert, modicon m340 bmxp341000 firmware, modicon m340 bmxp342000 firmware, modicon m340 bmxp342010 firmware, modicon m340 bmxp3420102 firmware, modicon m340 bmxp342020 firmware, modicon m340 bmxp342020h firmware, modicon m340 bmxp342030 firmware, modicon m340 bmxp3420302 firmware, modicon m340 bmxp3420302h firmware, modicon m340 bmxp342030h firmware
- Weakness
- CWE-294
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H