PT-2022-3625 · Unknown · Opc Ua Modicon Communication Module+1

Published

2022-07-12

·

Updated

2022-07-27

·

CVE-2022-34763

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions X80 advanced RTU Communication Module versions 2.01 and later OPC UA Modicon Communication Module versions 1.10 and prior
Description A vulnerability exists due to insufficient verification of data authenticity, which could cause the loading of unauthorized firmware images. This is a result of improper verification of the firmware signature. The issue may allow a remote attacker to cause a denial of service.
Recommendations For X80 advanced RTU Communication Module versions 2.01 and later, update the firmware to a version that properly verifies the authenticity of firmware images. For OPC UA Modicon Communication Module versions 1.10 and prior, update the firmware to a version that properly verifies the authenticity of firmware images. As a temporary workaround, consider restricting access to the firmware update mechanism to minimize the risk of exploitation.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04410
CVE-2022-34763

Affected Products

Opc Ua Modicon Communication Module
X80 Advanced Rtu Communication Module