CVE-2021-22791

MEDIUMCVSS 6.5/10EPSS 0.80%

Last modified

CVE-2021-22791 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).. EPSS estimates a 0.80% chance of exploitation in the next 30 days.

Description

A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.80%

52.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Schneider-ElectricModicon M340 Bmxp341000All versions
Schneider-ElectricModicon M340 Bmxp342010All versions
Schneider-ElectricModicon M340 Bmxp342020All versions
Schneider-ElectricModicon M340 Bmxp342030All versions
Schneider-ElectricModicon M580 Bmeh582040All versions
Schneider-ElectricModicon M580 Bmeh582040cAll versions
Schneider-ElectricModicon M580 Bmeh582040sAll versions
Schneider-ElectricModicon M580 Bmeh584040All versions
Schneider-ElectricModicon M580 Bmeh584040cAll versions
Schneider-ElectricModicon M580 Bmeh584040sAll versions
Schneider-ElectricModicon M580 Bmeh586040All versions
Schneider-ElectricModicon M580 Bmeh586040cAll versions
Schneider-ElectricModicon M580 Bmeh586040sAll versions
Schneider-ElectricModicon M580 Bmep581020All versions
Schneider-ElectricModicon M580 Bmep581020hAll versions
Schneider-ElectricModicon M580 Bmep582020All versions
Schneider-ElectricModicon M580 Bmep582020hAll versions
Schneider-ElectricModicon M580 Bmep582040All versions
Schneider-ElectricModicon M580 Bmep582040hAll versions
Schneider-ElectricModicon M580 Bmep582040sAll versions
Schneider-ElectricModicon M580 Bmep583020All versions
Schneider-ElectricModicon M580 Bmep583040All versions
Schneider-ElectricModicon M580 Bmep584020All versions
Schneider-ElectricModicon M580 Bmep584040All versions
Schneider-ElectricModicon M580 Bmep584040sAll versions
Schneider-ElectricModicon M580 Bmep585040All versions
Schneider-ElectricModicon M580 Bmep585040cAll versions
Schneider-ElectricModicon M580 Bmep586040All versions
Schneider-ElectricModicon M580 Bmep586040cAll versions
Schneider-ElectricModicon Mc80 Bmkc8020301All versions
Schneider-ElectricModicon Mc80 Bmkc8020310All versions
Schneider-ElectricModicon Mc80 Bmkc8030311All versions
Schneider-ElectricModicon Momentum 171cbu78090All versions
Schneider-ElectricModicon Momentum 171cbu98090All versions
Schneider-ElectricModicon Momentum 171cbu98091All versions
Schneider-ElectricModicon Premium Tsxp57 1634mAll versions
Schneider-ElectricModicon Premium Tsxp57 2634mAll versions
Schneider-ElectricModicon Premium Tsxp57 2834mAll versions
Schneider-ElectricModicon Premium Tsxp57 454mAll versions
Schneider-ElectricModicon Premium Tsxp57 4634mAll versions
Schneider-ElectricModicon Premium Tsxp57 554mAll versions
Schneider-ElectricModicon Premium Tsxp57 5634mAll versions
Schneider-ElectricModicon Premium Tsxp57 6634mAll versions
Schneider-ElectricModicon Quantum 140cpu65150All versions
Schneider-ElectricModicon Quantum 140cpu65150cAll versions
Schneider-ElectricModicon Quantum 140cpu65160All versions
Schneider-ElectricModicon Quantum 140cpu65160cAll versions
Schneider-ElectricPlc Simulator For Ecostruxure Control ExpertAll versions
Schneider-ElectricPlc Simulator For Ecostruxure Process ExpertAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-22791?
A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).
How severe is CVE-2021-22791?
CVE-2021-22791 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.80% probability of exploitation in the next 30 days.
How do I fix CVE-2021-22791?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-22791?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST