CVE-2021-22746: Low severity schneider electric triconex model 3009 mp vulnerability
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22745, and CVE-2021-22747.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22746?
CVE-2021-22746 has a medium severity rating due to its potential to cause module resets.
How do I fix CVE-2021-22746?
To mitigate CVE-2021-22746, update the Triconex Model 3009 MP to a firmware version greater than 11.8.0.
Which systems are affected by CVE-2021-22746?
CVE-2021-22746 affects Triconex Model 3009 MP systems running Tricon V11.3.x.
What are the potential consequences of CVE-2021-22746?
The improper check can lead to unexpected module resets when maliciously crafted TriStation packets are received.
Is there a workaround for CVE-2021-22746?
A temporary workaround may include maintaining the write-protect keyswitch in the off position during operation.