PT-2021-7077 · Schneider Electric · Modicon M580 Cpu+4
CVE-2021-22779
·
Published
2021-07-13
·
Updated
2022-10-03
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
EcoStruxure Control Expert versions prior to V15.0 SP1
EcoStruxure Process Expert (all versions)
SCADAPack RemoteConnect for x70 (all versions)
Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*)
Modicon M340 CPU (all versions - part numbers BMXP34*)
Description
The issue is related to an Authentication Bypass by Spoofing vulnerability that could allow unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller. This vulnerability may enable a remote attacker to gain access.
Recommendations
For EcoStruxure Control Expert versions prior to V15.0 SP1, update to V15.0 SP1 or later.
For EcoStruxure Process Expert, restrict access to the system until a fix is available.
For SCADAPack RemoteConnect for x70, consider disabling remote connections until a patch is released.
For Modicon M580 CPU and Modicon M340 CPU, restrict access to the controllers and avoid using the Modbus communication protocol until a fix is available.
At the moment, there is no information about a newer version that contains a fix for EcoStruxure Process Expert, SCADAPack RemoteConnect for x70, Modicon M580 CPU, and Modicon M340 CPU.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Control Expert
Ecostruxure Process Expert
Modicon M340 Cpu
Modicon M580 Cpu
Scadapack Remoteconnect For X70