PT-2022-3762 · Schneider Electric · Modicon M340 Cpu+4
Published
2022-04-12
·
Updated
2022-11-30
·
CVE-2022-0222
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Modicon M340 CPUs versions prior to V3.40
Modicon M340 X80 Ethernet Communication modules: BMXNOE0100 (H), BMXNOE0110 (H)
BMXNOE* all versions
BMXNOR* versions prior to v1.7 IR24
Description
A vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. This issue is related to improper privilege management. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service by sending specially crafted requests.
Recommendations
For Modicon M340 CPUs versions prior to V3.40, update to version V3.40 or later to resolve the issue.
For BMXNOE* all versions, consider disabling SNMP access until a patch is available.
For BMXNOR* versions prior to v1.7 IR24, update to version v1.7 IR24 or later to resolve the issue.
As a temporary workaround, consider restricting access to the SNMP service to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmxnoe
Bmxnoe0100
Bmxnoe0110
Bmxnor
Modicon M340 Cpu