PT-2022-3762 · Schneider Electric · Modicon M340 Cpu+4

Published

2022-04-12

·

Updated

2022-11-30

·

CVE-2022-0222

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Modicon M340 CPUs versions prior to V3.40 Modicon M340 X80 Ethernet Communication modules: BMXNOE0100 (H), BMXNOE0110 (H) BMXNOE* all versions BMXNOR* versions prior to v1.7 IR24
Description A vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. This issue is related to improper privilege management. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service by sending specially crafted requests.
Recommendations For Modicon M340 CPUs versions prior to V3.40, update to version V3.40 or later to resolve the issue. For BMXNOE* all versions, consider disabling SNMP access until a patch is available. For BMXNOR* versions prior to v1.7 IR24, update to version v1.7 IR24 or later to resolve the issue. As a temporary workaround, consider restricting access to the SNMP service to minimize the risk of exploitation.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-04552
CVE-2022-0222

Affected Products

Bmxnoe
Bmxnoe0100
Bmxnoe0110
Bmxnor
Modicon M340 Cpu