First published: Tue Nov 22 2022(Updated: )
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80 Ethernet Communication modules:BMXNOE0100 (H), BMXNOE0110 (H), BMXNOR0200H RTU(BMXNOE* all versions)(BMXNOR* versions prior to v1.7 IR24)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M340 Bmxp341000 Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp341000 | ||
Schneider-electric Modicon M340 Bmxp342000 Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp342000 | ||
Schneider-electric Modicon M340 Bmxp342010 Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp342010 | ||
Schneider-electric Modicon M340 Bmxp3420102 Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp3420102 | ||
Schneider-electric Modicon M340 Bmxp342020 Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp342020 | ||
Schneider-electric Modicon M340 Bmxp342020h Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp342020h | ||
Schneider-electric Modicon M340 Bmxp342030 Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp342030 | ||
Schneider-electric Modicon M340 Bmxp3420302 Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp3420302 | ||
Schneider-electric Modicon M340 Bmxp3420302h Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp3420302h | ||
Schneider-electric Modicon M340 Bmxp342030h Firmware | <3.50 | |
Schneider-electric Modicon M340 Bmxp342030h | ||
Schneider-electric Modicon M340 Bmxnoe0100 Firmware | ||
Schneider-electric Modicon M340 Bmxnoe0100 | ||
Schneider-electric Modicon M340 Bmxnoe0110 Firmware | ||
Schneider-electric Modicon M340 Bmxnoe0110 | ||
Schneider-electric Modicon M340 Bmxnoe0110h Firmware | ||
Schneider-electric Modicon M340 Bmxnoe0110h | ||
Schneider-electric Modicon M340 Bmxnor0200h Firmware | ||
Schneider-electric Modicon M340 Bmxnor0200h |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-0222.
The severity of CVE-2022-0222 is high with a severity value of 7.5.
The CWE ID of CVE-2022-0222 is CWE-269.
The affected products are Modicon M340 CPUs (BMXP34* versions prior to V3.40) and Modicon M340 X80 Ethernet Communication.
To fix CVE-2022-0222, update the Modicon M340 CPUs to version V3.40 or higher.