PT-2021-7686 · Unknown · Triconex Model 3009 Mp
Published
2021-05-11
·
Updated
2021-06-07
·
CVE-2021-22742
CVSS v2.0
4.3
Medium
| Vector | AV:L/AC:L/Au:M/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Triconex Model 3009 MP versions 11.3.x
Description
The issue is related to an improper check for unusual or exceptional conditions, which could cause a module reset when the Triconex Communications Module (TCM) receives malformed TriStation packets. This can occur when the write-protect keyswitch is in the program position. The vulnerability may allow an attacker to cause a denial of service using specially crafted TriStation packets.
Recommendations
For Triconex Model 3009 MP version 11.3.x, consider disabling the reception of TriStation packets when the write-protect keyswitch is in the program position as a temporary workaround until a patch is available. Restrict access to the TCM to minimize the risk of exploitation. Avoid using the TriStation protocol in the affected systems until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Triconex Model 3009 Mp