A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80 Ethernet Communication modules:BMXNOE0100 (H), BMXNOE0110 (H), BMXNOR0200H RTU(BMXNOE* all versions)(BMXNOR* versions prior to v1.7 IR24)
References
Link | Resource |
---|---|
https://www.se.com/us/en/download/document/SEVD-2022-102-02/ | Vendor Advisory |
https://www.se.com/us/en/download/document/SEVD-2022-102-02/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
History
21 Nov 2024, 06:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.se.com/us/en/download/document/SEVD-2022-102-02/ - Vendor Advisory |
30 Nov 2022, 20:38
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:schneider-electric:modicon_m340_bmxnor0200h:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp342030h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420302_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp342000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxnoe0100_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxnoe0110h:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp342010:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxnoe0100:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxnoe0110h_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp342010_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp342030h:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxnoe0110:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp342030:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420102:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp341000:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp341000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp3420302h:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp342000:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420102_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp342020h_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp342020_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp342030_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxnoe0110_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxnor0200h_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:modicon_m340_bmxp3420302h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m340_bmxp342020h:-:*:*:*:*:*:*:* |
|
References | (CONFIRM) https://www.se.com/us/en/download/document/SEVD-2022-102-02/ - Vendor Advisory | |
CWE | CWE-269 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
22 Nov 2022, 13:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-11-22 13:15
Updated : 2024-11-21 06:38
NVD link : CVE-2022-0222
Mitre link : CVE-2022-0222
CVE.ORG link : CVE-2022-0222
JSON object : View
Products Affected
schneider-electric
- modicon_m340_bmxp3420102
- modicon_m340_bmxp342020_firmware
- modicon_m340_bmxnoe0110h_firmware
- modicon_m340_bmxp342020
- modicon_m340_bmxp341000_firmware
- modicon_m340_bmxnoe0110_firmware
- modicon_m340_bmxp342030h
- modicon_m340_bmxnoe0110
- modicon_m340_bmxnor0200h_firmware
- modicon_m340_bmxp341000
- modicon_m340_bmxp3420302
- modicon_m340_bmxp342030_firmware
- modicon_m340_bmxp342020h_firmware
- modicon_m340_bmxp3420302h_firmware
- modicon_m340_bmxp342020h
- modicon_m340_bmxp342030h_firmware
- modicon_m340_bmxnor0200h
- modicon_m340_bmxp3420302h
- modicon_m340_bmxp342000
- modicon_m340_bmxp342010
- modicon_m340_bmxp342010_firmware
- modicon_m340_bmxp3420102_firmware
- modicon_m340_bmxnoe0110h
- modicon_m340_bmxnoe0100
- modicon_m340_bmxp342030
- modicon_m340_bmxp342000_firmware
- modicon_m340_bmxp3420302_firmware
- modicon_m340_bmxnoe0100_firmware
CWE
CWE-269
Improper Privilege Management