PT-2022-9278 · Schneider Electric · Modicon M218 Logic Controller

Published

2022-02-11

·

Updated

2022-02-18

·

CVE-2021-22800

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Modicon M218 Logic Controller versions prior to V5.1.0.6
Description A vulnerability exists due to improper input validation, which could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP.
Recommendations For versions prior to V5.1.0.6, update to a version newer than V5.1.0.6 to resolve the issue. As a temporary workaround, consider restricting access to network port 1105/TCP to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22800

Affected Products

Modicon M218 Logic Controller