CVE-2021-22779
Last modified
CVE-2021-22779 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*), that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Control Expert | < 15.0 |
| Schneider-Electric | Ecostruxure Control Expert | 15.0 |
| Schneider-Electric | Ecostruxure Process Expert | All versions |
| Schneider-Electric | Remoteconnect | All versions |
| Schneider-Electric | Modicon M580 Bmep581020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep581020h Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582020h Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582040h Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep582040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep583020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep583040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep584020 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep584040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep584040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep585040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep585040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep586040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmep586040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh582040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh582040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh582040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh584040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh584040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh584040s Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh586040 Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh586040c Firmware | All versions |
| Schneider-Electric | Modicon M580 Bmeh586040s Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp341000 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342010 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342020 Firmware | All versions |
| Schneider-Electric | Modicon M340 Bmxp342030 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22779?
How severe is CVE-2021-22779?
How do I fix CVE-2021-22779?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22772A CWE-306: Missing Authentication for Critical Function vuln…9.8
- CVE-2021-22773A CWE-620: Unverified Password Change vulnerability exists i…6.5
- CVE-2021-22774A CWE-759: Use of a One-Way Hash without a Salt vulnerabilit…7.5
- CVE-2021-22775A CWE-427: Uncontrolled Search Path Element vulnerability ex…7.8
- CVE-2021-22777A CWE-502: Deserialization of Untrusted Data vulnerability e…7.8
- CVE-2021-22778Insufficiently Protected Credentials vulnerability exists in…7.1
- CVE-2021-2278Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2021-22780Insufficiently Protected Credentials vulnerability exists in…7.1
- CVE-2021-22781Insufficiently Protected Credentials vulnerability exists in…5.5
- CVE-2021-22782Missing Encryption of Sensitive Data vulnerability exists in…5.5
- CVE-2021-22783A CWE-200: Information Exposure vulnerability exists which c…7.6
- CVE-2021-22784A CWE-306: Missing Authentication for Critical Function vuln…5.7
Are you affected by CVE-2021-22779?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
