CVE-2021-22779
Last modified
CVE-2021-22779 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Control Expert | < 15.0 |
| Schneider-Electric | Ecostruxure Control Expert | 15.0 |
| Schneider-Electric | Ecostruxure Process Expert | All versions |
| Schneider-Electric | Remoteconnect | All versions |
| Schneider-Electric | Modicon M580 Bmep581020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep581020h Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582020h Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582040h Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep583020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep583040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep584020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep584040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep584040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep585040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep585040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep586040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep586040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh582040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh582040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh582040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh584040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh584040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh584040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh586040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh586040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh586040s Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp341000 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342010 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342020 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342030 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22779?
How severe is CVE-2021-22779?
How do I fix CVE-2021-22779?
Are you affected by CVE-2021-22779?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
