CVE-2022-0222: High severity schneider electric modicon m340 bmxp341000 firmware vulnerability
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34 versions prior to V3.40), Modicon M340 X80 Ethernet Communication modules:BMXNOE0100 (H), BMXNOE0110 (H), BMXNOR0200H RTU(BMXNOE all versions)(BMXNOR versions prior to v1.7 IR24)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-0222.
What is the severity of CVE-2022-0222?
The severity of CVE-2022-0222 is high with a severity value of 7.5.
What is the CWE ID of CVE-2022-0222?
The CWE ID of CVE-2022-0222 is CWE-269.
Which products are affected by CVE-2022-0222?
The affected products are Modicon M340 CPUs (BMXP34* versions prior to V3.40) and Modicon M340 X80 Ethernet Communication.
How can I fix CVE-2022-0222?
To fix CVE-2022-0222, update the Modicon M340 CPUs to version V3.40 or higher.