First published: Wed Feb 01 2023(Updated: )
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP34*) (Versions prior to V3.30), Modicon M580 CPU (part numbers BMEP* and BMEH*) (Versions prior to SV3.20), Modicon MC80 (BMKC80) (Versions prior to V1.6), Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) (All Versions), Modicon Momentum MDI (171CBU*) (Versions prior to V2.3), Legacy Modicon Quantum (All Versions)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modicon M340 BMXP341000 Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP341000 | ||
Schneider Electric Modicon M340 BMXP342000 Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP342000 Firmware | ||
Schneider Electric Modicon M340 BMXP342010 Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP342010 Firmware | ||
Schneider Electric Modicon M340 BMXP3420102 Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP3420102 | ||
Schneider Electric Modicon M340 BMXP342020 Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP342020 | ||
Schneider Electric Modicon M340 BMXP342020H Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP342020H | ||
Schneider Electric Modicon M340 BMXP342030 Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP342030H | ||
Schneider Electric Modicon M340 BMXP3420302 Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP3420302 Firmware | ||
Schneider Electric Modicon M340 BMXP3420302H Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP3420302H Firmware | ||
Schneider Electric Modicon M340 BMXP342030H Firmware | <3.40 | |
Schneider Electric Modicon M340 BMXP342030H | ||
Schneider Electric Modicon M580 BMEH582040 Firmware | <=3.20 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <=3.20 | |
Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <=3.20 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEH584040 Firmware | <=3.20 | |
schneider-electric Modicon M580 bmeh584040c | ||
Schneider Electric Modicon M580 Firmware | <=3.20 | |
schneider-electric Modicon M580 bmeh584040c firmware | ||
Schneider Electric Modicon M580 BMEH584040S Firmware | <=3.20 | |
Schneider Electric Modicon M580 BMEH584040S Firmware | ||
Schneider Electric Modicon M580 | <=3.20 | |
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <=3.20 | |
Schneider Electric Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <=3.20 | |
Schneider Electric Modicon M580 | ||
Modicon M580 | <=3.20 | |
Schneider Electric Modicon M580 BMEP581020 | ||
schneider-electric Modicon M580 BMEP581020 firmware | <=3.20 | |
schneider-electric Modicon M580 BMEP581020H firmware | ||
Schneider Electric Modicon M580 BMEP582020 Firmware | <=3.20 | |
Modicon M580 | ||
Schneider Electric Modicon M580 Firmware | <=3.20 | |
Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <=3.20 | |
schneider-electric Modicon M580 | ||
schneider-electric Modicon M580 bmep582040h firmware | <=3.20 | |
schneider-electric Modicon M580 | ||
Schneider Electric Modicon M580 BMEP582040 Firmware | <=3.20 | |
Schneider Electric Modicon M580 BMEP582040S | ||
Schneider Electric Modicon M580 BMEP583020 Firmware | <=3.20 | |
Schneider Electric Modicon M580 BMEP583020 | ||
Schneider Electric Modicon M580 BMEP583040 Firmware | <=3.20 | |
Schneider Electric Modicon M580 BMEP583040 | ||
Schneider Electric Modicon M580 BMEP584020 Firmware | <=3.20 | |
Schneider Electric Modicon M580 BMEP584020 Firmware | ||
Schneider Electric Modicon M580 BMEP584040 Firmware | <=3.20 | |
Schneider Electric Modicon M580 BMEP584040 Firmware | ||
Schneider Electric Modicon M580 BMEP584040S Firmware | <=3.20 | |
Schneider Electric Modicon M580 BMEP584040S Firmware | ||
schneider-electric Modicon M580 BMEP585040C Firmware | <=3.20 | |
schneider-electric Modicon M580 BMEP585040C Firmware | ||
Schneider Electric Modicon M580 BMEP585040C Firmware | <=3.20 | |
schneider-electric Modicon M580 BMEP585040C Firmware | ||
schneider-electric Modicon M580 bmep586040c firmware | <=3.20 | |
schneider-electric modicon m580 bmep586040 firmware | ||
Schneider Electric Modicon M580 BMEP585040C Firmware | <=3.20 | |
schneider-electric Modicon M580 bmep586040c firmware | ||
Schneider Electric Modicon Momentum 171CBU78090 | <2.4 | |
Schneider Electric Modicon Momentum 171CBU78090 | ||
Schneider Electric Modicon Momentum 171CBU98090 | <2.4 | |
Schneider Electric Modicon Momentum 171CBU98090 | ||
Schneider Electric Modicon Momentum 171CBU98091 Firmware | <2.4 | |
Schneider Electric Modicon Momentum 171CBU98091 Firmware | ||
Schneider Electric Modicon MC80 BMKC8020301 | <1.70 | |
schneider-electric modicon mc80 bmkc8020301 firmware | ||
Modicon MC80 Firmware | <1.70 | |
Modicon MC80 Firmware | ||
Modicon MC80 Firmware | <1.70 | |
Schneider Electric Modicon MC80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22786 has been classified as a CWE-200: Information Exposure vulnerability, indicating a potentially high impact on the confidentiality of sensitive information stored in memory.
To mitigate CVE-2021-22786, apply updates to the Modicon M340 CPUs to versions V3.30 or later, and the Modicon M580 CPUs to versions V3.20 or later.
CVE-2021-22786 affects Schneider Electric Modicon M340 CPUs with part numbers BMXP34* and Modicon M580 CPUs with specific firmware versions prior to the mentioned updates.
CVE-2021-22786 can lead to the exposure of sensitive information stored in the memory of affected controllers during communication over the Modbus TCP protocol.
Yes, CVE-2021-22786 can be exploited remotely when the affected devices communicate over the Modbus TCP protocol without proper security measures.