CVE-2022-45788

CRITICALCVSS 9.8/10EPSS 1.16%

Last modified

CVE-2022-45788 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions), Modicon Momentum Unity M1E Processor - 171CBU* (All Versions), Modicon MC80 - BMKC80 (All Versions), Legacy Modicon Quantum - 140CPU65* and Premium CPUs - TSXP57* (All Versions) . EPSS estimates a 1.16% chance of exploitation in the next 30 days.

Description

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions), Modicon Momentum Unity M1E Processor - 171CBU* (All Versions), Modicon MC80 - BMKC80 (All Versions), Legacy Modicon Quantum - 140CPU65* and Premium CPUs - TSXP57* (All Versions)

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.16%

63.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Schneider-ElectricEcostruxure Control ExpertAll versions
Schneider-ElectricEcostruxure Process Expert< 2021
Schneider-ElectricModicon M340 Bmxp341000 FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp342000 FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp342010 FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp3420102 FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp342020 FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp342020h FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp342030 FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp3420302 FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp3420302h FirmwareAll versions
Schneider-ElectricModicon M340 Bmxp342030h FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh582040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh582040c FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh582040s FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh584040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh584040c FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh584040s FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh586040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh586040c FirmwareAll versions
Schneider-ElectricModicon M580 Bmeh586040s FirmwareAll versions
Schneider-ElectricModicon M580 Bmep581020 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep581020h FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582020 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582020h FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582040h FirmwareAll versions
Schneider-ElectricModicon M580 Bmep582040s FirmwareAll versions
Schneider-ElectricModicon M580 Bmep583020 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep583040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep584020 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep584040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep584040s FirmwareAll versions
Schneider-ElectricModicon M580 Bmep585040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep585040c FirmwareAll versions
Schneider-ElectricModicon M580 Bmep586040 FirmwareAll versions
Schneider-ElectricModicon M580 Bmep586040c FirmwareAll versions
Schneider-ElectricModicon Momentum 171cbu78090 FirmwareAll versions
Schneider-ElectricModicon Momentum 171cbu98090 FirmwareAll versions
Schneider-ElectricModicon Momentum 171cbu98091 FirmwareAll versions
Schneider-ElectricModicon Mc80 Bmkc8020301 FirmwareAll versions
Schneider-ElectricModicon Mc80 Bmkc8020310 FirmwareAll versions
Schneider-ElectricModicon Mc80 Bmkc8030311 FirmwareAll versions
Schneider-ElectricModicon Quantum 140cpu65150 FirmwareAll versions
Schneider-ElectricModicon Quantum 140cpu65150c FirmwareAll versions
Schneider-ElectricModicon Quantum 140cpu65160 FirmwareAll versions
Schneider-ElectricModicon Quantum 140cpu65160c FirmwareAll versions
Schneider-ElectricModicon Premium Tsxp57 1634m FirmwareAll versions
Schneider-ElectricModicon Premium Tsxp57 2634m FirmwareAll versions
Schneider-ElectricModicon Premium Tsxp57 2834m FirmwareAll versions

Showing 50 of 55 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-45788?
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions), Modicon Momentum Unity M1E Processor - 171CBU* (All Versions), Modicon MC80 - BMKC80 (All Versions), Legacy Modicon Quantum - 140CPU65* and Premium CPUs - TSXP57* (All Versions)
How severe is CVE-2022-45788?
CVE-2022-45788 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.16% probability of exploitation in the next 30 days.
How do I fix CVE-2022-45788?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-45788?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST