Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-05 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
03 Feb 2022, 16:14
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:se:modicon_m241_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:o:schneider-electric:modicon_m251_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:* |
31 Jan 2022, 19:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:se:modicon_m241:-:*:*:*:*:*:*:* |
cpe:2.3:h:schneider-electric:modicon_m251:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m241:-:*:*:*:*:*:*:* |
26 Aug 2021, 14:43
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:schneider-electric:modicon_m241:-:*:*:*:*:*:*:* |
cpe:2.3:h:se:modicon_m241:-:*:*:*:*:*:*:* cpe:2.3:h:se:modicon_m251:-:*:*:*:*:*:*:* |
19 Aug 2021, 18:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:o:se:modicon_m251_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:se:modicon_m241_firmware:*:*:*:*:*:*:*:* |
04 Jun 2021, 15:19
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:schneider-electric:modicon_m251:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m241:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m251_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 7.8
v3 : 7.5 |
References | (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-05 - Vendor Advisory |
26 May 2021, 20:49
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 |
26 May 2021, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-05-26 20:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-22699
Mitre link : CVE-2021-22699
CVE.ORG link : CVE-2021-22699
JSON object : View
Products Affected
schneider-electric
- modicon_m251_firmware
- modicon_m241
- modicon_m241_firmware
- modicon_m251
CWE
CWE-20
Improper Input Validation