CVE-2022-22724: High severity schneider electric modicon m340 bmxp341000 firmware vulnerability
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22724.
What is the severity of CVE-2022-22724?
The severity of CVE-2022-22724 is high (7.5).
What does CVE-2022-22724 involve?
CVE-2022-22724 involves an Uncontrolled Resource Consumption vulnerability that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus) when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC.
Which products are affected by CVE-2022-22724?
The Modicon M340 CPUs with the following firmware versions are affected: BMXP341000, BMXP342000, BMXP342010, BMXP3420102, BMXP342030, BMXP3420302.
How can I fix CVE-2022-22724?
To fix CVE-2022-22724, it is recommended to apply the latest firmware updates provided by Schneider-electric Modicon M340.