PT-2021-7077 · Schneider Electric · Modicon M580 Cpu+4

CVE-2021-22779

·

Published

2021-07-13

·

Updated

2022-10-03

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions EcoStruxure Control Expert versions prior to V15.0 SP1 EcoStruxure Process Expert (all versions) SCADAPack RemoteConnect for x70 (all versions) Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*) Modicon M340 CPU (all versions - part numbers BMXP34*)
Description The issue is related to an Authentication Bypass by Spoofing vulnerability that could allow unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller. This vulnerability may enable a remote attacker to gain access.
Recommendations For EcoStruxure Control Expert versions prior to V15.0 SP1, update to V15.0 SP1 or later. For EcoStruxure Process Expert, restrict access to the system until a fix is available. For SCADAPack RemoteConnect for x70, consider disabling remote connections until a patch is released. For Modicon M580 CPU and Modicon M340 CPU, restrict access to the controllers and avoid using the Modbus communication protocol until a fix is available. At the moment, there is no information about a newer version that contains a fix for EcoStruxure Process Expert, SCADAPack RemoteConnect for x70, Modicon M580 CPU, and Modicon M340 CPU.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03220
CVE-2021-22779

Affected Products

Ecostruxure Control Expert
Ecostruxure Process Expert
Modicon M340 Cpu
Modicon M580 Cpu
Scadapack Remoteconnect For X70