PT-2021-7686 · Unknown · Triconex Model 3009 Mp

Published

2021-05-11

·

Updated

2021-06-07

·

CVE-2021-22742

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:M/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Triconex Model 3009 MP versions 11.3.x
Description The issue is related to an improper check for unusual or exceptional conditions, which could cause a module reset when the Triconex Communications Module (TCM) receives malformed TriStation packets. This can occur when the write-protect keyswitch is in the program position. The vulnerability may allow an attacker to cause a denial of service using specially crafted TriStation packets.
Recommendations For Triconex Model 3009 MP version 11.3.x, consider disabling the reception of TriStation packets when the write-protect keyswitch is in the program position as a temporary workaround until a patch is available. Restrict access to the TCM to minimize the risk of exploitation. Avoid using the TriStation protocol in the affected systems until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01588
CVE-2021-22742

Affected Products

Triconex Model 3009 Mp