PT-2021-7830 · Schneider Electric · Modicon Mc80+7

Published

2021-08-10

·

Updated

2021-09-13

·

CVE-2021-22790

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Modicon M580 CPU versions all Modicon M340 CPU versions all Modicon MC80 versions all Modicon Momentum Ethernet CPU versions all PLC Simulator for EcoStruxure Control Expert versions all PLC Simulator for EcoStruxure Process Expert versions all Modicon Quantum CPU versions all Modicon Premium CPU versions all
Description The issue is related to a buffer read overflow in memory, which could allow a remote attacker to cause a denial of service. This is a result of a specially crafted project file being used to update the controller application.
Recommendations For Modicon M580 CPU, update to a version that includes a fix for this issue. For Modicon M340 CPU, update to a version that includes a fix for this issue. For Modicon MC80, update to a version that includes a fix for this issue. For Modicon Momentum Ethernet CPU, update to a version that includes a fix for this issue. For PLC Simulator for EcoStruxure Control Expert, update to a version that includes a fix for this issue. For PLC Simulator for EcoStruxure Process Expert, update to a version that includes a fix for this issue. For Modicon Quantum CPU, update to a version that includes a fix for this issue. For Modicon Premium CPU, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the controller application until a patch is available.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03448
CVE-2021-22790

Affected Products

Modicon M340 Cpu
Modicon M580 Cpu
Modicon Mc80
Modicon Momentum Ethernet Cpu
Modicon Premium Cpu
Modicon Quantum Cpu
Plc Simulator For Ecostruxure Control Expert
Plc Simulator For Ecostruxure Process Expert