PT-2023-1236 · Schneider Electric · Ecostruxure Process Expert+4

CVE-2022-45789

·

Publicado

2023-01-10

·

Atualizado

2023-10-19

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure Control Expert versions prior to V2020 EcoStruxure Process Expert versions prior to V2020 Modicon M340 CPU versions prior to the latest version Modicon M580 CPU versions prior to the latest version Modicon M580 CPU Safety versions prior to the latest version
Description A CWE-294: Authentication Bypass by Capture-replay issue exists, allowing execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. This could impact the confidentiality, integrity, and availability of protected information.
Recommendations For EcoStruxure Control Expert versions prior to V2020, update to version V2020 or later. For EcoStruxure Process Expert versions prior to V2020, update to version V2020 or later. For Modicon M340 CPU, Modicon M580 CPU, and Modicon M580 CPU Safety, update to the latest version. As a temporary workaround, consider restricting access to the Modbus session to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-00485
CVE-2022-45789

Produtos afetados

Ecostruxure Control Expert
Ecostruxure Process Expert
Modicon M340 Cpu
Modicon M580 Cpu
Modicon M580 Cpu Safety