First published: Wed Jul 13 2022(Updated: )
A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to improper handling of the cookies. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Opc Ua Module For M580 Firmware | <=1.10 | |
Schneider-electric Opc Ua Module For M580 | ||
Schneider-electric X80 Advanced Rtu Module Firmware | =1.0 | |
Schneider-electric X80 Advanced Rtu Module |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34760 has a severity rating that indicates it can cause a denial of service due to an infinite loop issue.
To mitigate CVE-2022-34760, update to the latest firmware version of the affected Schneider Electric devices as recommended by the vendor.
CVE-2022-34760 affects the Schneider Electric X80 Advanced RTU Communication Module V1.0 and the OPC UA Modicon Communication Module with firmware versions up to 1.10.
CVE-2022-34760 is classified as a CWE-835 vulnerability, which involves a loop with an unreachable exit condition leading to potential denial of service.
The impact of CVE-2022-34760 on a system could result in the webserver becoming unresponsive due to improper cookie handling.